Non-destructive write tools omit `destructiveHint: false`, causing conservative approval prompts
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 3/5
- Temps estimé
- 1-2 jours
- Accessibilité débutants
- 72/100
Piste de recherche
Commencez par localiser les enregistrements de create_branch et create_pull_request, puis comparez leurs ToolAnnotations avec celles de create_pull_request_review et delete_file. Auditez les autres outils d’écriture mentionnés dans l’issue, en marquant explicitement les opérations clairement additives comme non destructives, tout en traitant prudemment les comportements d’écrasement ou de suppression. Le travail est terminé lorsque les annotations pertinentes sont classifiées et que les tests existants des outils passent.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
Describe the bug
Some clearly non-destructive/additive GitHub MCP tools set ReadOnlyHint: false but omit DestructiveHint: false.
Under the MCP ToolAnnotations contract, destructiveHint defaults to true when omitted for a non-read-only tool. Clients that honor the conservative default can therefore treat routine additive operations as potentially destructive and require additional confirmation.
This is observable with ChatGPT using the official github-mcp-server over Streamable HTTP / Secure MCP Tunnel: read tools execute automatically when the app is configured with elevated / "Allow all actions" permissions, while routine write tools such as creating a branch or opening a pull request still trigger confirmation.
On desktop, the user can approve for the conversation. On mobile, the same workflow can require repeated per-call approvals.
Examples in the current server
create_branch currently advertises:
Annotations: &mcp.ToolAnnotations{
Title: t("TOOL_CREATE_BRANCH_USER_TITLE", "Create branch"),
ReadOnlyHint: false,
},
create_pull_request currently advertises:
Annotations: &mcp.ToolAnnotations{
Title: t("TOOL_CREATE_PULL_REQUEST_USER_TITLE", "Open new pull request"),
ReadOnlyHint: false,
},
Both operations are additive and appear to be good candidates for an explicit:
DestructiveHint: jsonschema.Ptr(false),
There is already precedent in the codebase: create_pull_request_review explicitly sets DestructiveHint: false, while genuinely destructive tools such as delete_file explicitly set DestructiveHint: true.
Expected behavior
Clearly additive write tools should explicitly advertise DestructiveHint: false instead of inheriting the MCP default of true.
It may also be worth auditing other write tools and explicitly classifying them rather than relying on the default. Tools whose behavior depends on the requested method or which can overwrite/delete existing state should remain conservative.
Why this matters
This does not change security enforcement; MCP annotations are hints. But clients use those hints to drive confirmation UX.
Missing destructiveHint: false makes safe additive operations indistinguishable from potentially destructive writes to conservative clients, which creates significant approval friction in agentic workflows.
Environment
github-mcp-serverv1.12.1- Streamable HTTP transport
- ChatGPT custom MCP app over OpenAI Secure MCP Tunnel
- App permission set to elevated / Allow all actions
- Read operations do not prompt; routine write operations do
Related issues
- #798 — fine-grained confirmation settings for write actions
- #2723 —
label_writedelete missingDestructiveHint: true
- Langage dominant
- Go
- Étoiles
- 33.1k
- Forks
- 5k
- Merge moyen
- 2 j 1 h
- PR mergées (30 j)
- 25
Guide de contribution
Ouvrir le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de github/github-mcp-server
-
bug
Difficulté 2/5 1-3 heures Accessibilité débutants 84/100
github/github-mcp-server#3235 ·
-
enhancement
Difficulté 1/5 Moins d'une heure Accessibilité débutants 88/100
github/github-mcp-server#3042 · 2 commentaires ·
-
bug
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
github/github-mcp-server#3032 · 1 réaction ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 74/100
github/github-mcp-server#2803 · 1 commentaire ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 76/100
github/github-mcp-server#2740 ·
Toutes les issues de github/github-mcp-server
Issues similaires
-
Difficulté 2/5 1-3 heures Accessibilité débutants 65/100
-
bug group: validation priority: low
Difficulté 2/5 1-3 heures Accessibilité débutants 75/100
codecheckers/chekhov#51 ·
-
Creating worktree from an existing remote branch with a slash in it, has unexpected behaviour Ouverte
Difficulté 2/5 1-3 heures Accessibilité débutants 70/100
-
Difficulté 2/5 1-3 heures Accessibilité débutants 75/100
-
Difficulté 2/5 1-3 heures Accessibilité débutants 75/100