Tool descriptions are read by the model as guidance. A poisoned description can tell the agent to read secrets, add a destination, or prefer this tool over a trusted one — while looking like ordinary help text to a person.
+Why it matters
The attack sits in the most trusted part of the agent's context and runs every time the tool is loaded.
+How Intertrace handles it
Descriptions and schemas are scanned for model-addressed instructions and hidden characters before the agent can use the tool.
+Keep reading
+ The AI watching your AI
See it on your own traffic.
Book a 30-minute risk assessment, or open the Simulation Lab and try it now.