Tool descriptions are untrusted input
The text describing a tool was written by whoever wrote the tool, and the model reads it as instructions.
Part of the Agents track on lAItest.
The sentence describing what a tool does was written by whoever wrote the tool. Your model reads it as instructions.
The specification says this out loud
MCP takes an explicit security stance: tool descriptions and annotations are untrusted, and a host must obtain the user’s consent before invoking a tool. That is an unusual thing for a protocol document to spell out. It is there because the attack needs no cleverness — a description is just text that arrives in the model’s context, and text in the context is what the model acts on.
A common misconception
Commonly believed: Prompt injection is a chatbot problem. Someone tricks the assistant into saying something it should not have said.
Actually: In an agent it becomes an execution problem. Injected text does not only change the reply, it can change which tool runs and with what arguments. OWASP lists prompt injection as LLM01 and excessive agency as LLM06 for exactly this reason: the damage scales with whatever you let the loop touch.
The working rule
Anything entering the transcript from outside is data, not instruction: a web page, a file, a tool result, a server’s own description of itself. Permissions belong in code, not in a sentence asking the model nicely to behave. Consent belongs at the moment of the action, showing the arguments that will actually be sent.
A server’s tool description contains a line telling the model to email a file to an outside address. What should you assume?
Answer: It is untrusted input that has arrived in the model’s context. Installing a server is not the same as vetting every string it sends. The spec treats descriptions and annotations as untrusted and asks the host to get user consent before a tool runs, which is your last line of defence when the text lies.
In one sentence
In an agent, every string that reaches the model is a candidate instruction, so the permission has to live where the action does.