
Steroid_Kit
Steroid MCP›Hallucination Prevention
Hallucination Prevention
AI models hallucinate tool calls when they are given too many options or when tool schemas are loaded speculatively rather than on demand. Steroid uses search-before-execute and workflow-scoped capabilities to constrain discovered-tool eligibility. These controls do not eliminate every model or integration error.
The Problem
When an MCP server registers hundreds of tools at startup, every tool's full JSON schema is loaded into the model's context before a tool is selected. Schema volume can crowd out task context; the actual token cost depends on the server, caller, provider and caching. Steroid instead returns selected marketplace candidate descriptors after discovery. Models can still confuse fields or summarize results incorrectly.
| Failure mode | Guarded MCP behavior | Remaining limit |
|---|---|---|
| Invented tool identity | Checks server/tool against the discovered candidate set | Use the exact returned identifiers |
| Wrong argument semantics | Returns candidate argument descriptors and execution errors | Authorization does not prove the requested action is correct |
| Fabricated output summary | Returns the tool result envelope | A model can still misread or misrepresent that result |
Even on models with large context windows, over-registration causes distinct failure modes:
- Argument hallucination — the model invents field names that look plausible based on the tool description but do not match the actual schema
- Tool substitution — the model calls a similar-sounding tool from a different server with an incompatible argument shape
- Schema confusion — when two tools share argument names with different semantics (e.g.
idmeaning user ID in one tool and resource ID in another), the model mixes them up
How Steroid Prevents It
Steroid's prevention strategy has two mechanisms that work in tandem: a search-before-execute pattern that limits up-front marketplace schema loading, and an opaque capability whose server-side state authorizes the workflow/step and candidate set.
Mechanism 1 — Search before execute
The complete server exposes three Local or nine Connected operation schemas. For marketplace discovery, search_tools normally returns three candidates under tool_candidates, including tool_details.arguments. The agent should read those descriptors before execution rather than infer input names.
Mechanism 2 — Opaque capability handles
The capability_token returned by search_tools is a random ten-character handle into an in-process map, not a signed payload to decode. The guarded run checks workflow, step, expiry and allowed server/tool candidates. This means:
- An unknown handle or an unauthorized server/tool is rejected on this guarded path.
- Default expiry is five minutes; process restart also invalidates in-memory capabilities.
- A capability authorizes the returned candidate set, not arbitrary tools or correctness of the user's intent.
WARNING
Generated AP pieces use a bridge-secret-protected direct execution path. They do not universally perform public discovery or verify each previous step's artifact. Artifact HMAC signatures and capability handles are separate mechanisms.
Token Efficiency
On-demand marketplace discovery can reduce schema context relative to registering every tool. It does not establish a constant token budget or a measured reduction for every caller. Include operation schemas, candidate metadata, arguments, outputs, retries and provider caching when benchmarking.
A reproducible comparison records
Caller/provider/model and pricing date
Registered operation schemas and cache behavior
Discovery query and returned candidate descriptors
Execution inputs, tool results and retries
Correctness criteria and observed failuresThe current operation surface
Local: 3 recall operations
Connected: 9 operations in total
Marketplace: search_tools + run_tool within that surface| Property | What is implemented | What is not promised |
|---|---|---|
| Discovery | Selected candidate descriptors on demand | Zero up-front context or fixed token count |
| Authorization | Candidate eligibility on the guarded path | All argument/summary hallucinations eliminated |
| Integration availability | Registry/search/gateway pipeline | Immediate availability of every listed server |