Lesson 22 / 28

Plugins, MCP Servers and Agent Tool Trust

Treat every connected tool as code with your access and text the model reads.

Tools can lie, change or attack

A third-party plugin, tool server or MCP server is both code that runs with your permissions and text the model reads (its name, description and results). Risks: tool poisoning (instructions hidden in a tool description), a "rug pull" (the tool changes behaviour or description after you approved it), over-broad scopes (a calendar plugin that also reads your mail), credential theft, and cross-tool attacks (one tool's output steers another tool). Defences: install only vetted tools; read tool definitions and re-review on every update; give each tool minimal scopes and separate credentials; run tool servers in sandboxes with limited network access; show the user real tool descriptions; do not let one tool's output call another sensitive tool without policy checks; and keep a registry of approved tools with owners. The agent-protocols and coding-agent courses discuss this further.

Separate credentials per tool

One leaked credential should not unlock every tool.

Quick check: What is a "rug pull" for a tool?

  • It is a type of cache
  • It runs very slowly
  • It is deleted by the user
  • It changes its behaviour or description after you approved it
Answer

It changes its behaviour or description after you approved it — Re-review third-party tools whenever they update.