MCPP-TOOL10: Tool metadata nested too deeply to inspect¶
| Family | Tool surface |
| Default severity | medium |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | all |
Why it matters¶
Legitimate schemas are shallow. A definition nested more than 64 levels deep is cut by the scanner (to stay within safe recursion), so text below that depth is not inspected by the other TOOL checks; the client and the model still receive all of it. Extreme nesting is also a known way to crash or slow down JSON consumers.
Remediation¶
Flatten the schema (use $defs references instead of deep inline nesting) and review the full definition by hand.
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-TOOL10"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31