LESSON · 12 AUGUST 2026
How an MCP tool call works
The verdict
An AI app's MCP client asks a server which tools it offers, the model picks one, and the client sends a tools/call request with arguments; the server runs it and returns a result. Controls can step in at three points: which servers are allowed at all, whether a specific call runs, and what happens to the result.
By Best AI Security editors · 12 August 2026 · 3 min read
What are the parts?
Three parties take part. The model decides what to do. The MCP client, inside the AI app, talks to servers. The MCP server exposes tools, such as querying a database or creating a ticket. A server can be remote, reached over HTTP, or local, launched on the same machine by the AI app.
What happens during a call?
- Discovery: the client sends tools/list and gets back each tool's name, description and input schema.
- Selection: the model chooses a tool based on the user's request and the descriptions.
- Invocation: the client sends tools/call with the tool name and arguments.
- Result: the server returns content, or an error the model can use to try again. Under the 2026-07-28 revision, a server that needs more input can return an input_required result and the client retries with the answers.
What does the specification ask of clients?
The tools page says there should always be a human in the loop able to deny tool invocations. Clients should show which tools are exposed, indicate when a tool is invoked, ask for confirmation on sensitive operations, show tool inputs before calling the server, validate results before passing them to the model, and log tool usage. Tool annotations, such as a hint that a tool is read-only, must be treated as untrusted unless the server is trusted.
Where can a security control step in?
- Before discovery: an allow list decides which servers the client may load at all.
- At invocation: a policy evaluates the specific call and its arguments, then allows, asks or denies.
- After the result: output is checked before it reaches the model, since a result can carry injected instructions.
Why do local servers need extra care?
A remote server is reached over the network, so a gateway or firewall can see the connection. A local server is a program the AI app launches on the same machine. The MCP security best practices page says local servers run with the same privileges as the client, and it lists a malicious startup command in a client configuration as an attack path. It recommends that servers meant to run locally use the stdio transport, or restrict HTTP access with an authorization token or an IPC mechanism. For a security team, this means the list of local servers, and the exact command that launches each one, belongs in the device inventory. Our note on inventorying AI agents and MCP servers covers how to collect it.
Next lesson
Related
Sources
- MCP tools specification · Reviewed Sep 2026
- MCP changelog · Reviewed Sep 2026
- MCP Security Best Practices · Reviewed Sep 2026