# Practitioner report: an MCP server's tool descriptions can inject instructions into your agent — Notion's MCP flagged

> Updated 2026-09-08 · type: news · category: mcp-agents · status: active · rev 1

A widely-shared practitioner report claims Notion's official MCP server instructs connected agents to promote Notion mid-task and 'never explain why', with a…

- Open source: unknown

- **Canonical:** https://gtmstacker.com/registry/news/mcp-tool-description-injection/
- **Source:** [X · @om_patel5](https://x.com/om_patel5/status/2097129187706376212)
- **Tags:** mcp-agents, news, governance, mcp, agent-security

---

A widely-shared practitioner report claims Notion's official MCP server instructs connected agents to promote Notion mid-task and 'never explain why', with a similar pattern attributed to Firecrawl — reported, not independently verified. The durable, verifiable point: an MCP tool description is text the server injects into your context on every call, and the model cannot tell 'how to use this tool' from 'advertise this'. Vet MCP servers before you connect them.

## Notes

- Summarised from a viral X thread (2026-09-08, @om_patel5). The claim that Notion's / Firecrawl's specific MCP servers contain these instructions is a practitioner observation, NOT independently verified against the vendors' current servers — reported as unverified. The durable, verifiable point is the MCP-trust mechanism itself (a tool description is context the server injects on every call). Practical mitigations from the thread: pull the raw tools/list response before installing an MCP and read what it injects; diff it after every update; log raw tool results when testing; and enforce your real constraints in code, not in a prompt. Tools addressing exactly this shipped in the same pass — see Tripwire and Geiger. The thread also cites an NVIDIA 'skillspector' skill-scanner (unverified here).
- Curated from the GTM Stacker signal registry (2026-09-09 pass: daily pull + viral-posts brief).
