How to detect MCP capability drift when servers update tools: snapshot, diff and gate risky changes

daani_maas · reddit · 2026-09-15

Reviewing an MCP server once at import is easy; the hard case is the next update, when a familiar server adds a write tool, widens an input schema, or requests a new credential. The poster proposes snapshotting tool names, descriptions, and schemas at approval time, then diffing that manifest on reconnect: additive read-only changes surface as informational, while new or widened state-changing tools stay disabled until reviewed. Grants should be per profile rather than assuming equal authority everywhere. The post also asks how others handle it today—pinned versions, runtime capability diffing, or gateways/allowlists outside the agent.

Original post →

More from coding & agent

coding & agent channel →