Everyone secures the MCP tool call. The leak is in tools/list.
中文摘要
即使代理无法执行工具,它们仍能通过 tools/list 获取完整的工具元数据,从而引发潜在的信息泄露风险。
English Summary
Even if agents are restricted from executing tools, they can still access full tool metadata via tools/list, causing potential information leaks.
Original Excerpt
An agent that will never be allowed to run a tool still gets its name, its description, and its full argument schema. Continue reading on Medium »