Once an AI agent can act, its tool descriptions become the trust boundary attackers target, not the prompts it reads.