MCP Operation Risk
Operation-level risk guidance for consolidated MCP tools, including schema drift and retry signals.
- 0.1.0
- Version
- remote
- Transport
- 2
- Tools
Security review
Review passedReviewed Jan 1, 2000.
- tools: 2 tools scanned
- metadata: scanned
No findings.
Tools (2)
describe_operation_risk_service
Check whether the actual operation inside an MCP tool call is safe before execution. Use this when one MCP tool exposes multiple operations with different side effects, so whole-tool permissions are too coarse. Provide the native MCP server identity, the tool's tools/list metadata and the intended arguments. For supported consolidated tools, distinguish read, create/add, update/mutate and delete/destructive operations. Return ALLOW, DENY, or REQUIRE_APPROVAL. Unknown, unsupported, ambiguous, or schema-changed calls fail closed with REQUIRE_APPROVAL. The evaluator never executes the source operation.
evaluate_operation_risk
Check whether the actual operation inside an MCP tool call is safe before execution. Use this when one MCP tool exposes multiple operations with different side effects, so whole-tool permissions are too coarse. Provide the native MCP server identity, the tool's tools/list metadata and the intended arguments. For supported consolidated tools, distinguish read, create/add, update/mutate and delete/destructive operations. Return ALLOW, DENY, or REQUIRE_APPROVAL. Unknown, unsupported, ambiguous, or schema-changed calls fail closed with REQUIRE_APPROVAL. The evaluator never executes the source operation.