mcp-tool

SI Readiness by MCP-Tool

Honest annotations on tools

Are read-only tools marked read-only, and is anything destructive gated behind confirmation?

Why it matters

Annotations are how an agent decides what it may do without asking. Marking your read paths readOnlyHint is what makes them safe to call freely — and the specification's own threat model is the reason anything that writes should pause for a human.

How to fix it

Set readOnlyHint on every tool that only reads. Set untrustedContentHint where a tool returns text written by other users. Put a confirmation step in front of anything that spends money or changes state.

Run a check · Full method