MCPP-TOOL03: Encoded blob in tool metadata¶
| Family | Tool surface |
| Default severity | medium |
| Confidence | medium |
| Mode | passive (default scan) |
| Spec revisions | all |
Why it matters¶
Base64, hex or percent-encoded payloads in a description serve no purpose for a human reader; models decode them readily, which makes them a way to hide instructions from reviewers.
Remediation¶
Remove encoded content from descriptions. If a format example is needed, keep it short and obviously illustrative.
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-TOOL03"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31