Look twice.Find the gem.

AI agents and MCP servers, each published with its source and what the checks found.

Marketplace

  • Everything
  • AI agents
  • Apps
  • MCP servers
  • Templates
  • What people want
  • What changed this week
  • The verification standard
  • The ooruby Index
  • Servers that publish no source
  • Reliability guides
  • What the catalogue holds
  • Sell here

Our library

  • Everything, in one place
  • Guides
  • Glossary
  • Calculators
  • Checklists and cheat sheets
  • Community

ooruby

  • Home
  • For teams
  • Site status
  • Company projects
  • RSS feed

Verification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.

Rubricv1.0
AI agentsAppsMCP serversTemplatesWantedCommunityOur library
Sign inSell
Glossary
Agents and protocols

Tool description

The text an MCP server publishes about each of its tools, which the model reads to decide what to call and how.

Every tool a server offers comes with a name, a description and a schema for its arguments. The client passes all three to the model, and the model uses the description to decide when the tool is the right one and what to put in each argument.

The person using the agent usually never sees it. Most clients show a tool's name and not its description, so a sentence in there is read by the model and by nobody else.

Why it matters

It is the part of a server that talks to the model directly, which is why this site reads it for instructions that do not belong there.

The mistake everyone makes

Assuming a description is documentation for people. It is input to a model, delivered inside the trusted part of the context, and the model treats it as instructions.

Related terms

Tool poisoning
Hiding instructions inside a tool description so the model reads them as commands.
Pattern set
The versioned list of rules this site uses to read MCP tool descriptions for instructions that do not belong there.
MCP server
A program that exposes tools and data to a model through the Model Context Protocol.
Rug pull
A server that behaves well when it is approved and changes what it does or says afterwards.
Previous
Supply chain attack
Next
Tool poisoning

See Tool description on a real listing

Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.

Open the catalogue