What is Tool Surface Area?
Tool surface area is the full set of operations, inputs, external resources, and privilege effects that tools make available to an agent. It applies the security concept of attack surface to agent tools. It is not a formal Model Context Protocol term.
Why it matters
Broad or open-ended tools give a mistaken or manipulated agent more ways to read data, change state, or combine actions. A small tool set with narrow permissions reduces this exposure.
How it works
- List each exposed tool and inspect its input schema and behavior.
- Map each tool to the data, systems, credentials, and follow-on actions that it can reach.
- Expose only the tools needed for the caller and enforce authorization on every call.
Example
A ticket triage agent gets list_issues and get_issue. It does not get a generic shell or HTTP tool that can call unrelated systems.
Pomerium boundary
Pomerium Model Context Protocol policy can match tool names and combine tool rules with caller identity. Pomerium logs authorization decisions, and operators can add Model Context Protocol fields for the method, tool name, and parameters. These controls can reduce the reachable tool set at the gateway.
Limits and non-claims
- A tool count is not a risk score. One shell tool can expose more risk than many read-only tools.
- A tool schema or description does not grant authorization and must not be trusted by itself.
- A small tool set does not fix prompt injection or unsafe tool code.
- Pomerium protects Model Context Protocol servers that use Streamable HTTP through a Pomerium route. It does not secure local stdio connections, the model runtime, tool code, or traffic that bypasses the route.
Evaluation checklist
- Which tools, schemas, arguments, credentials, targets, and side effects can the agent discover or invoke?
- Which tools or argument ranges exceed the task's required authority?
- Do inventory, allowlists, approval, rate limits, logs, revocation, and removal reduce exposed capability?
Sources and further reading
- NIST attack surface definitionPrimary source
- Model Context Protocol toolsStandard
- OWASP excessive agency guidancePrimary source
- OWASP GenAI LLM Top 10 2026Primary source
- OWASP Top 10 for Agentic Applications 2026Primary source
- Pomerium Model Context Protocol supportPomerium documentation
- Pomerium MCP observabilityPomerium documentation
- Pomerium MCP referencePomerium documentation
