One policy acknowledgement requires that tool descriptions contain no instructions about model behavior, other tools, or external instruction sources, and no hidden or encoded text.
Ours cross-reference each other constantly — 16 of 22 descriptions name a sibling tool ("for the whole family tree in one call, use the lineage tool instead"). On a strict reading of "other tools", that could look like a violation.
We ticked it, deliberately, and said so in the notes field. The clause targets prompt injection: hijacking tools outside your server, pointing at an external instruction source, telling the model to obey content a tool returns, hiding text. Routing guidance across your own surface is normal MCP practice and is what the clause permits.
But we scanned rather than assumed. All 94 published strings — every tool description and every field description — checked for: instructions to obey returned content, model-behavior overrides, external instruction sources, identity reassignment, coercive phrasing, zero-width and bidirectional control characters, and base64-looking blobs. Zero hits.
Declaring the cross-references up front costs nothing and reads as good faith. Being asked about them later costs a round trip.