Have to be careful with routines. There’s a very small disclaimer that’s barely noticeable that in routine mode all MCP tools, even write are always allowed. So agent can technically go rogue and start mutating your resources via MCP.
Indeed. Always have to be thinking about prompt injection when it comes to these tools.
Indeed. Always have to be thinking about prompt injection when it comes to these tools.