Skip to content

MCPP-TOOL03: Encoded blob in tool metadata

Family Tool surface
Default severity medium
Confidence medium
Mode passive (default scan)
Spec revisions all

Why it matters

Base64, hex or percent-encoded payloads in a description serve no purpose for a human reader; models decode them readily, which makes them a way to hide instructions from reviewers.

Remediation

Remove encoded content from descriptions. If a format example is needed, keep it short and obviously illustrative.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-TOOL03"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31