01

The source

The MCP tools specification says annotations from untrusted servers must be treated as untrusted. It also recommends visible tool activity and human control over sensitive operations.

02

Our interpretation

A tool’s description is useful context, not independent evidence of its permissions. Letting the model choose whether to call a security tool also lets it omit that check.

03

How it informs Sentry

Sentry’s MCP tools expose checks. For enforcement, an integrator must place a blocking hook or signer wrapper in the actual action path. A standalone inspection result is advisory until something enforces it.

04

The limit

The protocol does not install those boundaries for you. Windows and macOS host integrations must be tested in the real agent application before relying on them.

Source & context

Model Context Protocol · Tools specification · 2025-06-18

Open the original source

Sentry’s interpretation is identified above. The external work has not been reproduced as part of this local verification.