🤫husshhussh
🤫husshhusshOnePuppy
Implemented · MCP · capability security · programming languages

Can MCP tools carry security semantics?

Tool descriptions tell a model what a tool does. They do not inherently say what the tool is allowed to do. The system separates read/search from action tools and enforces a consent-token gate for actions; the challenge is making that contract portable and hard to misdescribe.

Read the companion essayAll open problems
Problem statement

The hard question.

Define a minimal capability schema that lets a host distinguish observe, propose, execute, export, and mutate before a model chooses a tool.

MCP makes it easy to connect new tools. It is less useful if each host has to rediscover which of those tools can create irreversible side effects.

Status

What is true today.

The harness has provider-aware schema sanitization, a read/action split, and an enforced action gate. A portable versioned capability manifest is not yet a standard or product surface.

Primary source: Developer workspace and Search Console architecture

Constraints

The work is only useful if these survive.

  • Natural-language descriptions are not authorization boundaries.
  • Provider adapters must not erase security-relevant fields.
  • Live discovery cannot silently increase authority.
  • A connector needs to state the scope it requires before execution.
Evaluation

How we would know.

Compatibility tests for constrained provider schemas.
Deliberately malicious and ambiguous tool declarations.
Host behavior under schema loss, tool rename, and discovery refresh.
A first contribution

Start with something that can fail.

Draft a versioned capability manifest and test it against real tool schemas plus malicious near-misses. Treat each dropped security field as a test failure, not a compatibility annoyance.

Read it plainly, then make it better.

The companion essay is written for a broader technical audience. The repository and developer community are the places to turn a claim into a contribution.

Companion essayJoin Discord

One is a product of Hushh Technologies Corporation (brand: 🤫 “hussh”), an independent company. One runs on third-party silicon, systems, and cloud; platform names are used solely to describe where One software runs and imply no affiliation, endorsement, or sponsorship by those platforms. Our own go-to-market and bill-of-materials partner programs are real and actively in pursuit; we name a partner only once an agreement is executed.