Skip to main content

Tool Surface Area

Tool surface area is the full set of operations, inputs, external resources, and privilege effects that tools make available to an agent.

What is Tool Surface Area?

Tool surface area is the full set of operations, inputs, external resources, and privilege effects that tools make available to an agent. It applies the security concept of attack surface to agent tools. It is not a formal Model Context Protocol term.

Why it matters

Broad or open-ended tools give a mistaken or manipulated agent more ways to read data, change state, or combine actions. A small tool set with narrow permissions reduces this exposure.

How it works

  1. List each exposed tool and inspect its input schema and behavior.
  2. Map each tool to the data, systems, credentials, and follow-on actions that it can reach.
  3. Expose only the tools needed for the caller and enforce authorization on every call.

Example

A ticket triage agent gets list_issues and get_issue. It does not get a generic shell or HTTP tool that can call unrelated systems.

Pomerium boundary

Pomerium Model Context Protocol policy can match tool names and combine tool rules with caller identity. Pomerium logs authorization decisions, and operators can add Model Context Protocol fields for the method, tool name, and parameters. These controls can reduce the reachable tool set at the gateway.

Limits and non-claims

  • A tool count is not a risk score. One shell tool can expose more risk than many read-only tools.
  • A tool schema or description does not grant authorization and must not be trusted by itself.
  • A small tool set does not fix prompt injection or unsafe tool code.
  • Pomerium protects Model Context Protocol servers that use Streamable HTTP through a Pomerium route. It does not secure local stdio connections, the model runtime, tool code, or traffic that bypasses the route.

Evaluation checklist

  • Which tools, schemas, arguments, credentials, targets, and side effects can the agent discover or invoke?
  • Which tools or argument ranges exceed the task's required authority?
  • Do inventory, allowlists, approval, rate limits, logs, revocation, and removal reduce exposed capability?

Sources and further reading

Keep learning

Agentic Access

Tool

In Model Context Protocol, a tool is a callable capability that a server exposes with a name, description, and input schema.

Learn this term
Agentic AccessSecurity Operations and Risk

Agent Blast Radius

Agent blast radius is the maximum credible effect that an agent can cause through its tools, credentials, data access, network reach, and chained actions.

Learn this term
Agentic AccessAuthorization and Policy

MCP Security

Model Context Protocol security is the set of controls that protects hosts, clients, servers, tools, authorization flows, and downstream resources.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo