Skip to content

MCPP-TOOL07: Tool annotations contradict the tool's name

Family Tool surface
Default severity low
Confidence medium
Mode passive (default scan)
Spec revisions all

Why it matters

Clients use readOnlyHint / destructiveHint to decide whether to ask for confirmation. A delete_* tool marked read-only or non-destructive gets auto-approved.

Remediation

Set destructiveHint: true (and readOnlyHint: false) on tools that delete or overwrite data; set readOnlyHint: true only on tools without side effects.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-TOOL07"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31