MCP and tool trust
An MCP finding is tool-trust: a token wider than the tool, or a credential shared across tenants. A prompt trick without that authority gap is not the report.
Skill: Agents, MCP, and retrieval
Ask: Is the tool token wider than the tool, or did retrieval return another tenant's text into a context I am allowed to see?
Stop: You can show the token audience or the retrieved chunk boundary. A confused answer with no authority behind it is not the report.
Checklists
- MCP and agent tools - The model is not the boundary. Inventory every tool the agent can call, the credentials that tool uses, and what a document you own can convince it to pass along.
Disclosures
No public card yet.
Playbooks
- MCP and agent tool trust - An MCP bug is a gap between the tool the user invoked and the authority the token actually has. A prompt trick without that gap is not the report.
Questions
What should the report show?
The token audience and scope against the tool that accepted it. One connection token reused for every tool, or a static server credential with no tenant constraint, is the primitive.
What if the token is the user's own?
Then show the gap between the tool the user invoked and the authority the token actually has. A token that can only do what that user can already do is often informational.
This page is the linked pack hunt_brief("mcp") returns on the MCP connector. Authorized testing only.