A reader made a point on my last post that I couldn't answer at the time, so I went and measured it.
The point: "tool added" is not automatically a safe change. I'd been filing additions under harmless because every old invocation still validates against its schema. But validation isn't selection. A new overlapping tool can capture calls that used to route somewhere else, and nothing errors — the agent just quietly starts doing something different.
I said name-overlap was the obvious first approximation and clearly incomplete. It is both of those things. Here's what it shows.
The measurement
377 registry-listed MCP servers that complete an anonymous handshake, 7,164 tools, every pair within each server compared — 170,345 pairs. A pair gets flagged when the names share most of their tokens, or the descriptions overlap heavily, or both moderately.






