MCP Tools
MCP tools are the callable actions an MCP server exposes for a connected client to invoke.
Prerequisites
What Are MCP Tools?
MCP tools are the actions an MCP server makes available — each one defined with a schema describing its name, purpose, and expected input, following the same tool-schema pattern used in tool calling generally. What's different is how they're discovered: instead of being hardcoded into an agent's configuration, MCP tools are found dynamically when a client connects to a server.
{
"name": "search_codebase",
"description": "Search the connected repository for a code pattern",
"inputSchema": {
"type": "object",
"properties": {
"query": { "type": "string" },
"fileType": { "type": "string" }
},
"required": ["query"]
}
}The Lifecycle of an MCP Tool Call
Client Discovers Tool
Dynamic DiscoveryFound at connect time, not hardcoded in config.
Model Decides to Use It
Model ChoosesDecides the tool fits the current task.
Client Sends Call
Structured RequestMatches the tool's declared input schema.
Server Executes
Real ExecutionThe server, not the model, actually runs it.
Result Returned
Back to ClientSent back through the same connection.
Important
The result an MCP tool returns is content the server produced — like any tool result, it should be treated as data the model reasons about, not as trusted instructions.
Common Mistakes
Treating MCP tool results as inherently trustworthy
A tool result from an MCP server is still external content — the same untrusted-content handling from prompt injection and agent security applies.
Assuming every discovered MCP tool should always be used
Just because a tool is discoverable doesn't mean it's appropriate for the agent's current task or permission level.
Writing an MCP tool description no more carefully than an internal note
A connecting model relies entirely on the description to use the tool correctly — the same quality bar from tool schemas applies here.
Interview Question
What are MCP tools, and how does their discovery differ from tools defined directly in an agent's own configuration?
MCP tools are the callable actions an MCP server exposes, each defined with a schema describing its name, purpose, and expected input — the same underlying pattern as any tool schema. What's different is discovery: instead of being hardcoded into an agent's own configuration ahead of time, MCP tools are found dynamically when a client connects to a server, so an agent can gain new capabilities just by connecting to a new server rather than being reconfigured. A tool's result still needs to be treated as untrusted external content, the same as any other tool result, since it comes from outside the application.
What an interviewer may ask next
- How does an agent discover MCP tools compared to tools defined in its own configuration?
- Should an MCP tool result be trusted differently than any other tool result?
- What determines whether a discovered MCP tool is actually appropriate to use for a given task?
Explain It in 30 Seconds
MCP tools are the callable actions an MCP server exposes, each defined with a schema like any other tool. The key difference is discovery: they're found dynamically when a client connects to a server, rather than hardcoded into an agent's configuration ahead of time — so an agent gains capability just by connecting to a new server. Their results still need the same untrusted-content treatment as any other tool result.