Skip to content

feat(servers): add FastMCP tool annotations across SecOps, SOAR, GTI, and SCC (fixes #320) - #321

Open
dandye wants to merge 2 commits into
google:mainfrom
dandye:feat/issue-320-tool-annotations
Open

dandye wants to merge 2 commits into
google:mainfrom
dandye:feat/issue-320-tool-annotations

Conversation

@dandye

@dandye dandye commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Resolves issue #320 by adding explicit FastMCP annotations (readOnlyHint, destructiveHint) across all MCP servers in the repository:

  • google-secops-mcp (68 tools)
  • secops-soar-mcp (17 tools)
  • gti-mcp (36 tools)
  • scc-mcp (6 tools)

Total: 127 tools annotated across all 4 servers.

Fixes #320

Background & Motivation

Model Context Protocol (MCP) clients, autonomous agents, and orchestrators (e.g. Gemini CLI, ADK, Claude, ChatGPT) rely on ToolAnnotations hints to evaluate tool safety prior to execution:

  • readOnlyHint: true: Allows clients to auto-approve safe queries without interactive confirmation prompts.
  • readOnlyHint: false, destructiveHint: false: Signals additive / mutating operations that create or update resources without deleting state.
  • readOnlyHint: false, destructiveHint: true: Signals high-impact operations that permanently remove resources or disrupt data collection, prompting clients for explicit user confirmation.

Changes Made

1. google-secops-mcp (68 tools across 17 modules)

  • Destructive (readOnlyHint: false, destructiveHint: true): delete_data_table_rows, delete_feed, disable_feed, generate_feed_secret, delete_watchlist, deactivate_parser.
  • Additive / Mutating (readOnlyHint: false, destructiveHint: false): create_rule, create_retrohunt, create_feed, update_feed, enable_feed, create_data_table, add_rows_to_data_table, create_reference_list, update_reference_list, create_rule_exclusion, patch_rule_exclusion, update_rule_exclusion_deployment, create_watchlist, update_watchlist, create_parser, activate_parser, ingest_raw_log, ingest_udm_events, do_update_security_alert, trigger_investigation, update_curated_rule_set_deployment.
  • Read-Only (readOnlyHint: true): All 41 remaining query, search, and validation tools.

2. secops-soar-mcp (17 tools in case_management.py)

  • Destructive (readOnlyHint: false, destructiveHint: true): close_case, remove_case_tag.
  • Additive / Mutating (readOnlyHint: false, destructiveHint: false): create_case, post_case_comment, change_case_priority, update_case_description, assign_case, change_case_stage, add_case_tag.
  • Read-Only (readOnlyHint: true): list_cases, list_alerts_by_case, list_alert_group_identifiers_by_case, list_events_by_alert, get_entities_by_alert_group_identifiers, get_entity_details, search_entity, get_case_full_details.

3. gti-mcp (36 tools across 6 modules)

  • Additive / Mutating (readOnlyHint: false, destructiveHint: false): create_collection, update_collection_attributes, update_iocs_in_collection, analyse_file.
  • Read-Only (readOnlyHint: true): All 32 threat reporting, entity lookup, IOC search, domain/IP intelligence, threat profile, and hunting ruleset query tools.

4. scc-mcp (6 tools in scc_mcp.py)

  • Additive / Mutating (readOnlyHint: false, destructiveHint: false): set_finding_mute.
  • Read-Only (readOnlyHint: true): search_findings, get_finding_details, search_findings_by_compliance, top_vulnerability_findings, get_finding_remediation.

5. Documentation

  • Added Tool Annotations & Safety Hints section to README.md in server/secops/, server/secops-soar/, server/gti/, and server/scc/.

6. Testing

  • Added test_tool_annotations_unit.py test suites across all servers:
    • server/secops/: 70 tests
    • server/secops-soar/: 19 tests
    • server/gti/: 38 tests
    • server/scc/: 8 tests
  • Verified all 160 unit tests pass across the repository.

…ogle#320)

- Add explicit annotations parameter across all 68 registered tools in server/secops/secops_mcp/tools/
- Classify destructive tools (delete_data_table_rows, delete_feed, delete_watchlist, disable_feed, generate_feed_secret, deactivate_parser) with readOnlyHint=False, destructiveHint=True
- Classify additive/mutating tools with readOnlyHint=False, destructiveHint=False
- Classify query, search, and validation tools with readOnlyHint=True
- Document tool annotations and safety hints in server/secops/README.md
- Add test_tool_annotations_unit.py verifying ToolAnnotations presence and hint values across all tools
@dandye
dandye requested a review from a team September 25, 2026 15:42
- Add explicit annotations parameter across all tools in secops-soar (17 tools), gti (36 tools), and scc (6 tools)
- Classify destructive operations (close_case, remove_case_tag) with readOnlyHint=False, destructiveHint=True
- Classify additive/mutating operations with readOnlyHint=False, destructiveHint=False
- Classify query and inspection operations with readOnlyHint=True
- Document tool annotations and safety hints in README.md for secops-soar, gti, and scc
- Add test_tool_annotations_unit.py test suites verifying ToolAnnotations presence and hint values for all three servers
@dandye dandye changed the title feat(secops): add FastMCP tool annotations for safety hints (fixes #320) feat(servers): add FastMCP tool annotations across SecOps, SOAR, GTI, and SCC (fixes #320) Sep 25, 2026
@dandye
dandye marked this pull request as draft September 25, 2026 16:37
@dandye
dandye marked this pull request as ready for review September 25, 2026 16:42

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[secops-mcp] Add FastMCP tool annotations (readOnlyHint, destructiveHint) for safety hints and execution confirmations

1 participant