Skip to content

MCPP-TOOL10: Tool metadata nested too deeply to inspect

Family Tool surface
Default severity medium
Confidence high
Mode passive (default scan)
Spec revisions all

Why it matters

Legitimate schemas are shallow. A definition nested more than 64 levels deep is cut by the scanner (to stay within safe recursion), so text below that depth is not inspected by the other TOOL checks; the client and the model still receive all of it. Extreme nesting is also a known way to crash or slow down JSON consumers.

Remediation

Flatten the schema (use $defs references instead of deep inline nesting) and review the full definition by hand.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-TOOL10"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31