MCP Error Messages Written for Developers Hurt the Most Capable Agents Most
Your tool server wraps a web API written for human developers, so when a token expires it returns something like "run: reddit-mcp-buddy --auth" — and the agent, which can only call tools, relays that to you and stops. Across 150 widely used servers, 949 of 3,001 error messages tell the caller what to do next and about half of those steps depend on something the server cannot see: on expired credentials 62 of 67 ask for a terminal command, a config edit or a web page. In 15,120 trials on five tool-only models the terminal-command step left 45% of turns recovered, and the damage scaled with capability — 18 points of lost recovery on the oldest model against 69 on the largest newest one, which made 0.60 tool calls per trial and handed the repair back to the user with the login tool sitting in its list. Both fixes are one line: name the server's own tool in the step (84% on credentials, 88% on rate limits once the message names the call to repeat), or delete the instruction sentence with a prompt before the model reads it (82%, nine cents across all 949 messages).