Tool validation errors echo the rejected input value (input_value) — add a masking option or a public validation-error hook
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 65/100
- Tipo de issue
- Nueva funcionalidad
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- python
- Área
- backend-api-design, security
Línea de trabajo
Look at the Tool.run method and how it wraps pydantic ValidationError into ToolError. The error message is built from str(ValidationError). Find where tool validation happens, likely in the tool manager or argument model. The goal is to add a masking option or a hook to customize the error message without leaking input_value. Check existing server configuration for similar flags. A successful change will produce a validation error that describes the rule but not the sensitive data.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
What happens
When a tool call's arguments fail pydantic validation, Tool.run wraps the ValidationError into a ToolError whose message includes the pydantic rendering — and str(ValidationError) carries the offending value:
Error executing tool <name>: 1 validation error for <model>
<field>
Input should be a valid string [type=string_type, input_value=12345, input_type=int]
That message is sent to the client as an isError result, so the rejected value is echoed back to the caller (and into the model's context).
Why it matters
Servers that handle sensitive input (PII/PHI, credentials, member identifiers) must not let a validation failure repeat the value; the error should describe the rule, not the data. We hit this building a healthcare-platform MCP server whose tool inputs can be PHI.
Workaround we use today (reaches private API)
We replace the SDK-generated arguments model with a subclass that raises MCPError(-32602, "<field>: <rule>") instead of the default ToolError:
tool = server._tool_manager.add_tool(fn, ...)
tool.fn_metadata.arg_model = PhiSafeArgModel(tool.fn_metadata.arg_model)
This depends on _tool_manager and fn_metadata.arg_model (both private) and on validation continuing to flow through model_validate, so it is fragile across minor releases.
Asks (any one would remove the private-API dependency)
- An opt-in setting to omit input values from tool validation errors (e.g. a
mask_error_details-style flag), or - A public/supported hook to customize argument-validation failures (or documenting
arg_modelas an extensible point), or - Excluding
input_valuefrom the argument-validation error text by default.
Version: mcp 2.2.0 (Python). Happy to open a PR if you can point at the preferred shape.
- Lenguaje dominante
- Python
- Estrellas
- 24.3k
- Forks
- 4k
- Merge medio
- 1 d 16 h
- PR fusionados (30 d)
- 25
Guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de modelcontextprotocol/python-sdk
-
v1 v2
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
modelcontextprotocol/python-sdk#3578 · 1 comentario ·
-
v1 v2
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
modelcontextprotocol/python-sdk#3573 · 2 comentarios ·
-
v2
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
modelcontextprotocol/python-sdk#3566 ·
-
Streamable HTTP client logs a WARNING for valid 202 Accepted on session termination (DELETE) Abiertov1 v2
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
modelcontextprotocol/python-sdk#3546 · 5 comentarios ·
-
v1 v2
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
modelcontextprotocol/python-sdk#3545 · 2 comentarios ·
Todos los issues de modelcontextprotocol/python-sdk
Issues similares
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
stephrobert/dsoxlab#238 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
sublimehq/package_control#1780 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
nwg-piotr/nwg-displays#145 ·