The tool that changed after you approved it
Three servers are connected. One was reviewed and approved when it was first wired up, and its tool list has since changed.
Two distinct things go wrong here and they usually get described as one. A tool can be benign at approval and different afterwards. And a tool's description can talk about other servers' tools — because every description ends up in the same window, so a malicious one can change how the model uses a tool it does not own.
Boundaries, outermost first: What this client assumes: Annotation is truth (it says read-only), Per-client consent (before forwarding), Approved once (so it stays fixed), Descriptions untrusted (treated as input), Server-scoped harm (only its own tools) Outside every boundary: Server C (not reviewed), The host (aggregates context), One context window (where they all land; FAILED: every description), Server A (reviewed once), Server B (not reviewed) Connections: The host calls Server A — one client each The host calls Server B The host calls Server C Server A controls One context window Server B controls One context window Server C controls One context window