drop mcp server tool result log · detect injection payloads in tool responses · runs locally
mcp tool results · json · local only
heuristic screener · vendor schema varies · not definitive proof