Vibeleaderboard
← All Intel
Intel / post

The quieter MCP risk: legitimate connectors with bad tool design

Source
x.com
Date
WRITER@Get_Writer

Everyone watches for the malicious MCP connector, one that's over-scoped and pointed at the wrong host. That's the obvious threat, and it gets the attention it deserves. There's a quieter risk, however, we see far more often, and it doesn't leak sensitive data. The connector is perfectly legitimate, but its tools just have bad descriptions, too many parameters, or vague instructions. Your agent doesn't get hacked so much as it confuses itself. It grabs the wrong tool, invents an argument, and burns through your token budget before you even get a chance to respond. From the user's side, both results look the same: "the agent did something I didn't want." But these are two distinct failure modes. One leaks data, while the other quietly erodes trust in your service. We think both deserve the same attention and discipline. Our MCP gateway was designed to deal with both. Every tool description gets scanned for prompt-injection poisoning before it's admitted to the registry. OAuth scopes get winnowed down by ~25% to fight context bloat. Tools get deterministic names so two connectors can expose "create_record" without forcing the agent to guess between meaningless suffixes, and…

Read the full post on X
Why it matters

Badly described MCP tools, with too many parameters or vague instructions, make agents pick the wrong tool, invent arguments and burn tokens without any attack. Mitigations include deterministic tool names, narrower OAuth scopes and hiding plumbing fields.

Key takeaways · AI-distilled
  • Writer argues a legitimate connector can still cause harm through poor tool design: vague descriptions, too many parameters or unclear instructions lead an to pick the wrong tool, invent arguments and burn .
  • From the user's side this looks identical to a security failure, the agent did something unwanted, but Writer frames it as a separate failure mode that erodes trust rather than leaking data.
  • Writer says its MCP gateway scans tool descriptions for prompt-injection poisoning before admitting them, trims OAuth scopes by about 25% to reduce bloat, and gives tools deterministic names so two connectors can both expose create_record.
  • The gateway also hides plumbing parameters from the model, so the agent cannot get a required but irrelevant field wrong.
Terms in this piece · Glossary
  • MCP — The Model Context Protocol — an open standard that lets any AI assistant plug into any tool or data source without custom integration code.
  • AI agent — An AI system that doesn't just answer once but works toward a goal in a loop — taking actions, reading the results, and deciding what to do next.
  • token — The chunk of text a model reads and writes in — roughly three-quarters of a word — and the unit AI usage is billed in.
  • context window — The maximum amount of text a model can consider at once — its working memory for the current conversation or task.
More from WRITER
Recommended reads
Comments

Checking sign-in…

Loading comments…