Threat
Tool misuse is harmful use of a real tool through valid-looking calls. The agent can select the wrong target, excessive scope, destructive operation, unsafe argument, repeated call, or dangerous sequence. The tool itself can work exactly as designed.
Authentication answers who reached the tool server. Tool authorization must still decide whether this actor may use this tool, resource, action, argument range, context, time, and volume.
Bound tool authority
Publish a small task-specific tool set. Separate read and write operations. Use typed schemas as input validation, then apply semantic rules for resource ownership, tenant, path, command, destination, amount, and state. Map each call to a named authorization action. Use narrow credentials that the tool server can use only at the required downstream resource.
Set quotas, concurrency limits, timeouts, and transaction boundaries. Make retries idempotent where possible. Require approval for high-impact actions after arguments are resolved. Record the actor, tool, target, policy, normalized arguments, decision, downstream result, and correlation identifier without storing credentials or unnecessary sensitive content.
Failure and residual risk
A valid JSON Schema can accept a dangerous path or command. A read tool can exfiltrate sensitive data. A sequence of individually allowed calls can create a prohibited result. Retry can duplicate payment, deletion, or message actions. A broad downstream credential can bypass the tool server's own checks.
The model can misstate the purpose of a call. Policy must evaluate facts and current resource state, not only the model's explanation.
Pomerium boundary
Pomerium can protect MCP server routes and apply caller policy. The tool server owns tool registration, input validation, per-resource authorization, downstream credential scope, execution safety, and result filtering. Route access is not permission to invoke every published tool.
Evaluation checklist
- Does each tool call map to an explicit resource and action?
- Are schemas supplemented by semantic, tenant, path, and state validation?
- Can a sequence of allowed calls create a prohibited outcome?
- Are retries, quotas, concurrency, and destructive operations controlled?
- Does the downstream credential have less authority than the tool server process?
