The source
The MCP tools specification says annotations from untrusted servers must be treated as untrusted. It also recommends visible tool activity and human control over sensitive operations.
Our interpretation
A tool’s description is useful context, not independent evidence of its permissions. Letting the model choose whether to call a security tool also lets it omit that check.
How it informs Sentry
Sentry’s MCP tools expose checks. For enforcement, an integrator must place a blocking hook or signer wrapper in the actual action path. A standalone inspection result is advisory until something enforces it.
The limit
The protocol does not install those boundaries for you. Windows and macOS host integrations must be tested in the real agent application before relying on them.
Model Context Protocol · Tools specification · 2025-06-18
Open the original sourceSentry’s interpretation is identified above. The external work has not been reproduced as part of this local verification.