# Plugins, MCP Servers and Agent Tool Trust — LLM Application Security

Source: https://www.geekswithgeeks.com/en/llm-security/p-agentsupply

> Treat every connected tool as code with your access and text the model reads.

## Tools can lie, change or attack

A third-party plugin, tool server or MCP server is both **code that runs with your permissions** and **text the model reads** (its name, description and results). Risks: **tool poisoning** (instructions hidden in a tool description), a **"rug pull"** (the tool changes behaviour or description after you approved it), **over-broad scopes** (a calendar plugin that also reads your mail), **credential theft**, and **cross-tool attacks** (one tool's output steers another tool). Defences: install only vetted tools; read tool definitions and **re-review on every update**; give each tool **minimal scopes and separate credentials**; run tool servers in **sandboxes with limited network access**; show the user real tool descriptions; **do not let one tool's output call another sensitive tool without policy checks**; and keep a **registry** of approved tools with owners. The agent-protocols and coding-agent courses discuss this further.

## Separate credentials per tool

One leaked credential should not unlock every tool.

**Quiz:** What is a "rug pull" for a tool?

- [ ] It is a type of cache
- [ ] It runs very slowly
- [ ] It is deleted by the user
- [x] It changes its behaviour or description after you approved it

*Answer:* It changes its behaviour or description after you approved it. Re-review third-party tools whenever they update.
