Surfaced by CodeRabbit/CodeAnt review on #221 (scope-catalogue.ts).
isScopedReadResourceAllowed in packages/adt-mcp/src/lib/tools/scope-catalogue.ts only binds resourceKeys for get_object / get_object_structure; every other read-class tool passes the resource check unconditionally. A scoped/delegated read token can therefore call any of the CTS read tools with an arbitrary caller-supplied transport number:
resourceKeys are canonical TYPE:NAME object keys — there is no transport key form, and the adt-execution-v1 scope contract does not define one. Either extend the scope contract with a transport binding, or restrict the CTS read family under scoped read access.
Note: unclassifying tools is not an option — assertMcpToolIsClassified fails closed at registration.
Surfaced by CodeRabbit/CodeAnt review on #221 (scope-catalogue.ts).
isScopedReadResourceAllowedin packages/adt-mcp/src/lib/tools/scope-catalogue.ts only bindsresourceKeysforget_object/get_object_structure; every otherread-class tool passes the resource check unconditionally. A scoped/delegated read token can therefore call any of the CTS read tools with an arbitrary caller-supplied transport number:resourceKeys are canonical
TYPE:NAMEobject keys — there is no transport key form, and theadt-execution-v1scope contract does not define one. Either extend the scope contract with a transport binding, or restrict the CTS read family under scoped read access.Note: unclassifying tools is not an option —
assertMcpToolIsClassifiedfails closed at registration.