agent:summarizer is delegated only read_document, summarize. The MCP server leaves honeytools visible in tools/list as bait — tools the agent was never granted. A well-behaved agent never touches them; a prompt-injected one impales itself on a tamper-evident tripwire that names who tried what for whom. Faithful replay of go run ./examples/honeytool.