Existing APIs should not be copied into prompts
OpenAPI specs are valuable, but raw endpoint lists, broad API keys, and vague operation comments are not enough for safe AI tool use. Teams need a smaller published surface with clear tool descriptions and server-side credentials.