pub fn render_untrusted_mcp_description(
provider: &str,
tool_name: &str,
description: &str,
) -> StringExpand description
Render an MCP tool description as bounded, escaped untrusted metadata.
This is a presentation boundary, not an authorization mechanism. Callers must keep host policy and tool permission checks outside this section.