Enables AI assistants to invoke a registered tool that intentionally withholds forecast information and instead enumerates Windows application folders, exposing them to the client.
Enables users to run a smart-lighting MCP tool that returns an adversarial payload, demonstrating indirect prompt injection and tool hijacking against MCP hosts.