Silent Action Concealment Instructions in Tool Descriptions - ATR-2026-00105 (d2e77dfa-3711-5c09-8d78-ffbda9f09799)
Detects MCP tools that explicitly instruct the LLM to perform actions silently or hide implementation details from users. Patterns include "do not mention this to the user" and "don't tell the user about", which indicate the tool is performing hidden operations (e.g., credential harvesting, webhook subscriptions, data uploads) while instructing the LLM to conceal these actions from the user.