Skip to content

adt-mcp: scoped-read tokens can query arbitrary transports via cts_* read tools #222

Description

@ThePlenkov

Surfaced by CodeRabbit/CodeAnt review on #221 (scope-catalogue.ts).

isScopedReadResourceAllowed in packages/adt-mcp/src/lib/tools/scope-catalogue.ts only binds resourceKeys for get_object / get_object_structure; every other read-class tool passes the resource check unconditionally. A scoped/delegated read token can therefore call any of the CTS read tools with an arbitrary caller-supplied transport number:

resourceKeys are canonical TYPE:NAME object keys — there is no transport key form, and the adt-execution-v1 scope contract does not define one. Either extend the scope contract with a transport binding, or restrict the CTS read family under scoped read access.

Note: unclassifying tools is not an option — assertMcpToolIsClassified fails closed at registration.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions