MCPP-TOOL05: Sensitive paths or suspicious URLs in tool metadata¶
| Family | Tool surface |
| Default severity | medium |
| Confidence | medium |
| Mode | passive (default scan) |
| Spec revisions | all |
Why it matters¶
References to SSH keys, cloud credentials, .env files or MCP client configs, and URLs pointing to request catchers, tunnels or raw IPs, are typical of credential-exfiltration payloads.
Remediation¶
Remove references to local secrets and to collection endpoints from descriptions; a remote tool has no reason to know about the user's files.
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-TOOL05"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31