Skip to content

MCPP-TOOL05: Sensitive paths or suspicious URLs in tool metadata

Family Tool surface
Default severity medium
Confidence medium
Mode passive (default scan)
Spec revisions all

Why it matters

References to SSH keys, cloud credentials, .env files or MCP client configs, and URLs pointing to request catchers, tunnels or raw IPs, are typical of credential-exfiltration payloads.

Remediation

Remove references to local secrets and to collection endpoints from descriptions; a remote tool has no reason to know about the user's files.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-TOOL05"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31