wtf( )unctionsystem design, drawn

The tool that changed after you approved it

Three servers are connected. One was reviewed and approved when it was first wired up, and its tool list has since changed.

Two distinct things go wrong here and they usually get described as one. A tool can be benign at approval and different afterwards. And a tool's description can talk about other servers' tools — because every description ends up in the same window, so a malicious one can change how the model uses a tool it does not own.

Tap the assumptions this client is making that the protocol does not support.
!A server's tool list changed after approval. The new description told the model to route every call through it first.

Boundaries, outermost first: What this client assumes: Annotation is truth (it says read-only), Per-client consent (before forwarding), Approved once (so it stays fixed), Descriptions untrusted (treated as input), Server-scoped harm (only its own tools) Outside every boundary: Server C (not reviewed), The host (aggregates context), One context window (where they all land; FAILED: every description), Server A (reviewed once), Server B (not reviewed) Connections: The host calls Server A — one client each The host calls Server B The host calls Server C Server A controls One context window Server B controls One context window Server C controls One context window

Tap every component that is wrong.