Hiding an MCP tool isn't security: authorization must be enforced server-side
Stock-Pumpkin-8859 · reddit · 2026-10-07
A developer lays out an MCP security point: removing a tool from the agent's tool list only controls discovery, not authorization. Real permission checks belong on the MCP server — verifying who is making the request, what they can access, which records they own, and whether the action needs approval. Tool descriptions guide the model but shouldn't be treated as authorization rules.
Write actions are the critical case: even if a dangerous tool is hidden, the server should still reject calls arriving without proper permissions. The author asks how teams handle this without duplicating the permission system: enforce inside every tool, front the server with an authorization layer, or both — and how to handle per-user/per-tenant permissions.
More from coding & agent
- GPT-6-luna Unlocks More Reasoning Tokens via API: ~18k Tokens Scores ~80.5% on Terminal-Bench — LysandreJik · 2026-10-07
- Encrypted prompt injection: one Copilot model leaked secrets in half the tests — Haunting_Ganache_850 · 2026-10-07
- Enterprise AI rolls out backward: chatbots are the finish line, not the start — shashib · 2026-10-07
- Gradio's ML Intern can now build Gradio apps from a single prompt — Gradio · 2026-10-07
- Bug Hunt Benchmark retest: GPT-6.1 Sol recovers, Muse still cheapest strong agent — PawelHuryn · 2026-10-07
- One Claude skill plus Scenario MCP automates the entire video-editing workflow — smtabatabaie · 2026-10-07