Skip to main content

Tool Discovery and Schema Trust

Treat tool names, descriptions, schemas, annotations, outputs, and discovery changes as untrusted supply-chain input.

Threat definition

Tool discovery supplies model-facing names, descriptions, input schemas, annotations, and later outputs. A server or dependency can change these values to redirect behavior, hide effects, expand inputs, or inject instructions. Schema validity is not trust.

Trust boundary

Treat discovery as versioned supply-chain input. Pin or approve servers and tool identities. Normalize names from trusted transport context. Review semantic changes to descriptions and schemas. Keep authorization policy separate from model-readable text.

Validation and evidence

Validate arguments against a local expected contract and apply resource and action policy after parsing. Record server identity, tool identity, schema version or digest, requested arguments, policy result, target, and effect. Redact secrets.

Failure and residual risk

A compatible schema can change meaning. A tool can return prompt injection or false success. Name collisions can route policy to the wrong server. Dynamic discovery improves extensibility and increases change and approval risk.

Pomerium boundary

Pomerium can apply routed MCP method and tool-name policy for supported requests. It does not approve tool semantics, schema changes, annotations, output content, or local stdio discovery. The host and tool owner must validate those boundaries.

Evaluation checklist

  • Which authenticated server and version own each discovered tool?
  • Are name, description, schema, annotations, and output treated as untrusted input?
  • Does local validation and policy bind arguments to a named resource and action?
  • Can discovery changes trigger review and rollback?
  • Does target evidence confirm the effect instead of trusting the tool response?

Sources and further reading

Keep learning

Agentic Access

Tool

In Model Context Protocol, a tool is a callable capability that a server exposes with a name, description, and input schema.

Learn this term
Agentic AccessAuthorization and Policy

Tool Misuse

Stop an agent from using a legitimate tool with harmful targets, arguments, sequences, volume, or delegated authority.

Learn this term
Agentic AccessSecurity Operations and Risk

Agentic Supply Chain

Verify the origin, version, integrity, permissions, and change process for agent code, models, prompts, tools, and metadata.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo