Why
r/mcp feedback (2026-08): a single whole-schema digest treats additive optional fields and legit vendor tool adds the same as a poisoned description. Without severity, quiet weeks of legit releases bury real rug pulls.
Cutting on top-level description vs inputSchema is the wrong cut: JSON Schema carries description/title per property, and those strings are still model-visible. Demoting them would miss the poison.
Proposal
Two digests, additive format bump (single fingerprint is load-bearing today):
- High-severity: every string the model reads (tool description, every description/title in input/output schema, annotations)
- Low-severity: structural residue (property names, types, required, enums, nesting)
Touches: SchemaRecord / store file, fingerprint_tools / digest(), heartbeat mcp_schema_digest, mcp_schema event, Splunk prev_schema compare, Sigma rule severity.
Not in scope for a drive-by
Do not demote property-level descriptions into the quiet bucket.
Source
Peer review on https://www.reddit.com/r/mcp/comments/1vvinyo/
Why
r/mcp feedback (2026-08): a single whole-schema digest treats additive optional fields and legit vendor tool adds the same as a poisoned description. Without severity, quiet weeks of legit releases bury real rug pulls.
Cutting on top-level
descriptionvsinputSchemais the wrong cut: JSON Schema carriesdescription/titleper property, and those strings are still model-visible. Demoting them would miss the poison.Proposal
Two digests, additive format bump (single fingerprint is load-bearing today):
Touches:
SchemaRecord/ store file,fingerprint_tools/digest(), heartbeatmcp_schema_digest,mcp_schemaevent, Splunkprev_schemacompare, Sigma rule severity.Not in scope for a drive-by
Do not demote property-level descriptions into the quiet bucket.
Source
Peer review on https://www.reddit.com/r/mcp/comments/1vvinyo/