Skip to content

13 of 15 tools annotated destructiveHint:true / readOnlyHint:false, but most are pure read/query operations #2118

Description

@vishalhabib99

Title: 13 of 15 tools annotated destructiveHint:true / readOnlyHint:false, but most are pure read/query operations

Body:

Querying tools/list on v0.10.8 (darwin-arm64 release binary), the tool annotations look like they were stamped with one shared default rather than set per-tool. Every tool except list_projects (correctly readOnlyHint: true) and ingest_traces gets the identical {"readOnlyHint": false, "destructiveHint": true, "idempotentHint": true, "openWorldHint": false}, including tools that only read/query and never mutate anything:

  • search_graph, query_graph, trace_path, get_code_snippet, get_graph_schema, get_architecture, search_code, index_status, check_index_coverage, detect_changes — all marked destructiveHint: true, readOnlyHint: false

By contrast, delete_project (an actual destructive op) gets the same annotation as get_architecture (a pure read) — so the hints don't currently distinguish "this deletes data" from "this reads a schema."

Why it matters: MCP clients and agent runtimes that respect these hints to gate auto-approval (e.g. only auto-run readOnlyHint: true tools without explicit user confirmation) will unnecessarily prompt for confirmation — or skip entirely — on 10 of your 15 tools that are actually safe reads. I hit this directly running a crash-fuzzing pass with mcp-fuzz, which only auto-tests readOnlyHint: true tools by default: it correctly tested just 1 of 15 tools until I explicitly opted into --include-destructive.

Real read-only candidates based on tool name/description: search_graph, query_graph, trace_path, get_code_snippet, get_graph_schema, get_architecture, search_code, index_status, check_index_coverage, detect_changes.

Happy to send more detail on the exact tools/list output if useful, but wanted to flag this first in case there's a reason for the current blanket annotation I'm missing.

Activity

  1. added
    bugSomething isn't working
    priority/highNeeds near-term maintainer attention; high-impact bug, regression, safety issue, or release blocker.
    and removed
    stability/performanceServer crashes, OOM, hangs, high CPU/memory
    parsing/qualityGraph extraction bugs, false positives, missing edges
    on Sep 9, 2026
  2. DeusData commented on Sep 9, 2026

    @DeusData
    Owner

    Thank you for the exact tools/list results and for explaining the effect on clients that use annotations for approval.

    This is already addressed on current main: the per-tool annotation table in src/mcp/mcp.c marks the ten query tools you listed as readOnlyHint: true and destructiveHint: false, while delete_project remains destructive. The query-only store paths are also described there as non-mutating; this is not just a blanket relabeling.

    Code checked:

    /* Tool annotations are deliberately explicit. All tools operate on the local

    The latest published release is still v0.10.8, so this does not mean your installed binary should already behave differently. We have labeled this as an integration bug and will keep the released-versus-main distinction explicit. Thank you for surfacing it.

  3. vishalhabib99 commented on Sep 9, 2026

    @vishalhabib99
    Author

    Appreciate the quick look and the exact commit reference — glad to hear it's already fixed on main. Makes sense to keep the released-vs-main distinction explicit given how directly this affects which tools a hint-respecting agent will actually call. Thanks for tracking it down.

  4. vishalhabib99 commented on Sep 26, 2026

    @vishalhabib99
    Author

    Closing, since this is fixed on main as you pointed out. Thanks again for the quick turnaround and the commit reference.

  5. added a commit that references this issue on Sep 30, 2026
  6. DeusData commented on Sep 30, 2026

    @DeusData
    Owner

    Thank you again for reporting this, @vishalhabib99! The fix is now on main in 083bc99 (merged via #2404), and it will ship in the next release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingeditor/integrationEditor compatibility and CLI integrationpriority/highNeeds near-term maintainer attention; high-impact bug, regression, safety issue, or release blocker.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions