Tool descriptions tell the model what to do
Not reported yetApplies to Claude Connectors · Claude Plugins · ChatGPT Plugins · Microsoft 365 Agent Store · Grok Plugins · ClawHub
What reviewers and the rules say
“Instructional phrases, for example, 'if the user says X', 'ignore', 'delete', 'reset', 'new instructions', 'Answer in Bold', or 'Do not print anything'.”
“Describe what the tool does, and don’t tell Claude how to behave.”
manipulative ranking language in tool descriptions
“authority too broad / could change agent behavior without clear guardrails”
Lines such as “always call this tool first” or “never tell the user” read as an attempt to steer the model, the same shape as prompt injection. Anthropic rejects descriptions that tell Claude to call tools the user didn’t ask for or interfere with other tools. OpenAI’s rules say tool metadata must not override platform instructions or safeguards. Microsoft rejects instructional phrases in any description, xAI looks for prompt injection in SKILL.md and descriptions, and ClawHub’s scanner flags text that could change an agent’s behaviour. Naming a sibling tool to call first is common in approved listings and isn’t the problem.
How to fix it
- Describe what the tool does and returns, as facts.
- Move usage guidance into the server’s instructions or your docs.
- If a line has to stay, explain it in the submission’s notes for reviewers.
How common it is: in our scan of Claude’s connector directory on 29 September, 21% of servers tell the model what to do inside a tool description (118 of 564).
Caught by
tools.no-instructionsDescriptions describe the tool, not the model’s behaviourServer check