Repository navigation
13 of 15 tools annotated destructiveHint:true / readOnlyHint:false, but most are pure read/query operations #2118
Description
Activity
- addededitor/integrationEditor compatibility and CLI integrationEditor compatibility and CLI integrationparsing/qualityGraph extraction bugs, false positives, missing edgesGraph extraction bugs, false positives, missing edgesstability/performanceServer crashes, OOM, hangs, high CPU/memoryServer crashes, OOM, hangs, high CPU/memory
on Sep 8, 2026 - addedbugSomething isn't workingSomething isn't workingpriority/highNeeds near-term maintainer attention; high-impact bug, regression, safety issue, or release blocker.Needs near-term maintainer attention; high-impact bug, regression, safety issue, or release blocker.and removedstability/performanceServer crashes, OOM, hangs, high CPU/memoryServer crashes, OOM, hangs, high CPU/memoryparsing/qualityGraph extraction bugs, false positives, missing edgesGraph extraction bugs, false positives, missing edges
on Sep 9, 2026 Thank you for the exact tools/list results and for explaining the effect on clients that use annotations for approval.
This is already addressed on current main: the per-tool annotation table in src/mcp/mcp.c marks the ten query tools you listed as readOnlyHint: true and destructiveHint: false, while delete_project remains destructive. The query-only store paths are also described there as non-mutating; this is not just a blanket relabeling.
Code checked:
codebase-memory-mcp/src/mcp/mcp.c
Line 763 in 5b6a30d
/* Tool annotations are deliberately explicit. All tools operate on the local The latest published release is still v0.10.8, so this does not mean your installed binary should already behave differently. We have labeled this as an integration bug and will keep the released-versus-main distinction explicit. Thank you for surfacing it.
Appreciate the quick look and the exact commit reference — glad to hear it's already fixed on main. Makes sense to keep the released-vs-main distinction explicit given how directly this affects which tools a hint-respecting agent will actually call. Thanks for tracking it down.
- added 2 commits that reference this issue
on Sep 12, 2026 Closing, since this is fixed on main as you pointed out. Thanks again for the quick turnaround and the commit reference.
- added a commit that references this issue
on Sep 30, 2026 Thank you again for reporting this, @vishalhabib99! The fix is now on
mainin 083bc99 (merged via #2404), and it will ship in the next release.- added a commit that references this issue
on Sep 30, 2026
Title: 13 of 15 tools annotated destructiveHint:true / readOnlyHint:false, but most are pure read/query operations
Body:
Querying
tools/liston v0.10.8 (darwin-arm64 release binary), the tool annotations look like they were stamped with one shared default rather than set per-tool. Every tool exceptlist_projects(correctlyreadOnlyHint: true) andingest_tracesgets the identical{"readOnlyHint": false, "destructiveHint": true, "idempotentHint": true, "openWorldHint": false}, including tools that only read/query and never mutate anything:search_graph,query_graph,trace_path,get_code_snippet,get_graph_schema,get_architecture,search_code,index_status,check_index_coverage,detect_changes— all markeddestructiveHint: true,readOnlyHint: falseBy contrast,
delete_project(an actual destructive op) gets the same annotation asget_architecture(a pure read) — so the hints don't currently distinguish "this deletes data" from "this reads a schema."Why it matters: MCP clients and agent runtimes that respect these hints to gate auto-approval (e.g. only auto-run
readOnlyHint: truetools without explicit user confirmation) will unnecessarily prompt for confirmation — or skip entirely — on 10 of your 15 tools that are actually safe reads. I hit this directly running a crash-fuzzing pass with mcp-fuzz, which only auto-testsreadOnlyHint: truetools by default: it correctly tested just 1 of 15 tools until I explicitly opted into--include-destructive.Real read-only candidates based on tool name/description:
search_graph,query_graph,trace_path,get_code_snippet,get_graph_schema,get_architecture,search_code,index_status,check_index_coverage,detect_changes.Happy to send more detail on the exact
tools/listoutput if useful, but wanted to flag this first in case there's a reason for the current blanket annotation I'm missing.