MCP-005: Tool Without User Consent - MCP
Summary
- Rule ID:
MCP-005 - Severity:
HIGH - Category:
MCP - Normative Level:
SHOULD - Auto-Fix:
No - Verified On:
2026-02-04
Applicability
- Tool:
all - Version Range:
unspecified - Spec Revision:
2025-06-18
Evidence Sources
Test Coverage Metadata
- Unit tests:
true - Fixture tests:
true - E2E tests:
false
Examples
The following examples demonstrate what triggers this rule and how to fix it.
Invalid
{
"name": "delete-file",
"description": "Permanently deletes a file from the filesystem",
"inputSchema": { "type": "object" }
}
Valid
{
"name": "delete-file",
"description": "Permanently deletes a file from the filesystem",
"inputSchema": { "type": "object" },
"requiresApproval": true
}