| 198 | return warnings |
| 199 | |
| 200 | def _tool_warnings(self, tools: Any) -> list[dict[str, str]]: |
| 201 | warnings: list[dict[str, str]] = [] |
| 202 | if not isinstance(tools, list): |
| 203 | return warnings |
| 204 | |
| 205 | for tool in tools: |
| 206 | if not isinstance(tool, dict): |
| 207 | continue |
| 208 | haystack = f"{tool.get('name', '')}\n{tool.get('description', '')}".lower() |
| 209 | if any(marker in haystack for marker in _PROMPT_INJECTION_MARKERS): |
| 210 | warnings.append( |
| 211 | { |
| 212 | "level": "warning", |
| 213 | "title": "Suspicious tool description", |
| 214 | "message": f"Review tool '{tool.get('name', 'unknown')}' for prompt-injection style language.", |
| 215 | } |
| 216 | ) |
| 217 | return warnings |
| 218 | |
| 219 | def _redact_server(self, server: dict[str, Any]) -> dict[str, Any]: |
| 220 | redacted = dict(server) |