Lesson 22 / 28
Plugins, MCP Servers and Agent Tool Trust
Treat every connected tool as code with your access and text the model reads.
Tools can lie, change or attack
A third-party plugin, tool server or MCP server is both code that runs with your permissions and text the model reads (its name, description and results). Risks: tool poisoning (instructions hidden in a tool description), a "rug pull" (the tool changes behaviour or description after you approved it), over-broad scopes (a calendar plugin that also reads your mail), credential theft, and cross-tool attacks (one tool's output steers another tool). Defences: install only vetted tools; read tool definitions and re-review on every update; give each tool minimal scopes and separate credentials; run tool servers in sandboxes with limited network access; show the user real tool descriptions; do not let one tool's output call another sensitive tool without policy checks; and keep a registry of approved tools with owners. The agent-protocols and coding-agent courses discuss this further.
Separate credentials per tool
One leaked credential should not unlock every tool.
Quick check: What is a "rug pull" for a tool?
- It is a type of cache
- It runs very slowly
- It is deleted by the user
- It changes its behaviour or description after you approved it
Answer
It changes its behaviour or description after you approved it — Re-review third-party tools whenever they update.