The quieter MCP risk: legitimate connectors with bad tool design
- Source
- x.com
- Date

Everyone watches for the malicious MCP connector, one that's over-scoped and pointed at the wrong host. That's the obvious threat, and it gets the attention it deserves. There's a quieter risk, however, we see far more often, and it doesn't leak sensitive data. The connector is perfectly legitimate, but its tools just have bad descriptions, too many parameters, or vague instructions. Your agent doesn't get hacked so much as it confuses itself. It grabs the wrong tool, invents an argument, and burns through your token budget before you even get a chance to respond. From the user's side, both results look the same: "the agent did something I didn't want." But these are two distinct failure modes. One leaks data, while the other quietly erodes trust in your service. We think both deserve the same attention and discipline. Our MCP gateway was designed to deal with both. Every tool description gets scanned for prompt-injection poisoning before it's admitted to the registry. OAuth scopes get winnowed down by ~25% to fight context bloat. Tools get deterministic names so two connectors can expose "create_record" without forcing the agent to guess between meaningless suffixes, and…

Badly described MCP tools, with too many parameters or vague instructions, make agents pick the wrong tool, invent arguments and burn tokens without any attack. Mitigations include deterministic tool names, narrower OAuth scopes and hiding plumbing fields.
- Writer argues a legitimate connector can still cause harm through poor tool design: vague descriptions, too many parameters or unclear instructions lead an to pick the wrong tool, invent arguments and burn .
- From the user's side this looks identical to a security failure, the agent did something unwanted, but Writer frames it as a separate failure mode that erodes trust rather than leaking data.
- Writer says its MCP gateway scans tool descriptions for prompt-injection poisoning before admitting them, trims OAuth scopes by about 25% to reduce bloat, and gives tools deterministic names so two connectors can both expose create_record.
- The gateway also hides plumbing parameters from the model, so the agent cannot get a required but irrelevant field wrong.
- MCP — The Model Context Protocol — an open standard that lets any AI assistant plug into any tool or data source without custom integration code.
- AI agent — An AI system that doesn't just answer once but works toward a goal in a loop — taking actions, reading the results, and deciding what to do next.
- token — The chunk of text a model reads and writes in — roughly three-quarters of a word — and the unit AI usage is billed in.
- context window — The maximum amount of text a model can consider at once — its working memory for the current conversation or task.
Checking sign-in…
Loading comments…





