How to detect MCP capability drift when servers update tools: snapshot, diff and gate risky changes
daani_maas · reddit · 2026-09-15
Reviewing an MCP server once at import is easy; the hard case is the next update, when a familiar server adds a write tool, widens an input schema, or requests a new credential. The poster proposes snapshotting tool names, descriptions, and schemas at approval time, then diffing that manifest on reconnect: additive read-only changes surface as informational, while new or widened state-changing tools stay disabled until reviewed. Grants should be per profile rather than assuming equal authority everywhere. The post also asks how others handle it today—pinned versions, runtime capability diffing, or gateways/allowlists outside the agent.
More from coding & agent
- Gemma via Exa MCP insists it's May 2024, returns stale data — iaderia · 2026-09-15
- Anthropic engineer behind Building Effective Agents explains agents in 14 minutes — HeyAmit_ · 2026-09-15
- Four dev boards hooked to the internet: test AI-written firmware on real silicon via HTTPS — SelfishlyWandering · 2026-09-15
- 'Mom, shhh, I'm talking to Devin AI': the meme every dev relates to — marvinvonhagen · 2026-09-15
- Social Quack launches: buy-once Mac scheduler with MCP hookup to Claude and ChatGPT — ThePeterMick · 2026-09-15
- Why enterprise AI pilots build a "tool museum" instead of capability — and the agentic-OS fix — Hamza_StrategizeLabs · 2026-09-15