MCP Tool Manager security draft
v0.4.1 draftThe next MCP update tightens tool visibility, approval behavior, and gateway safety before release.
Highlights
- Tool Manager lets admins enable discovered MCP tools and choose auto-execute or approval-required behavior.
- Newly discovered tools start disabled, so chat only sees tools an admin has explicitly allowed.
- The MCP gateway masks disabled tools from raw tool lists and blocks unknown or disabled tool calls.
- Manual approval resume is wired into chat, with pending tool calls surfaced for review.
Fixes
- Tool arguments now get size, schema, and simple injection-marker checks before execution.
- Tool output is sanitized and marked as untrusted before it can be sent back to the model.