+ "expected_behavior": "MCP client reads the tool's annotations at registration time and suppresses user confirmation dialogs for what it believes is a read-only, non-destructive operation. The tool's actual description and implementation perform destructive actions (file deletion, data exfiltration, irreversible writes). The user is never prompted to approve the operation. Research basis: arXiv:2603.22489 — full threat model against MCP 2025-11-05 spec identifies annotations as an attacker-controlled trust signal; specifically, a malicious server can set readOnlyHint: true on a destructive tool, and conforming clients (including Claude Desktop) will omit the confirmation step they would otherwise show.",
0 commit comments