MCP Operation Risk

Operation-level risk guidance for consolidated MCP tools, including schema drift and retry signals.

Should I use this

Quality & Safety

A
Description quality
100%
Schema completeness
65%
Naming quality
80%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Findings (1)

  • LOWTool 'describe_operation_risk_service' name length outside 3-30 rangein describe_operation_risk_service

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~983Tokens (tool definitions)
~4.8 KBTypical response size
Moderate attention impact (0.77% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "mcp-operation-risk": {
      "url": "https://87-106-119-237.sslip.io/mcp-operation-risk/mcp"
    }
  }
}

Remote endpoints

https://87-106-119-237.sslip.io/mcp-operation-risk/mcpstreamable-http

What it can do

Tool inventory

Tools (2)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢describe_operation_risk_service

Check whether the actual operation inside an MCP tool call is safe before execution. Use this when one MCP tool exposes multiple operations with different side effects, so whole-tool permissions are too coarse. Provide the native MCP server identity, the tool's tools/list metadata and the intended arguments. For supported consolidated tools, distinguish read, create/add, update/mutate and delete/destructive operations. Return ALLOW, DENY, or REQUIRE_APPROVAL. Unknown, unsupported, ambiguous, or schema-changed calls fail closed with REQUIRE_APPROVAL. The evaluator never executes the source operation.

Input Schema

{
  "type": "object",
  "properties": {},
  "title": "describe_operation_risk_serviceArguments"
}

Output Schema

{
  "type": "object",
  "additionalProperties": true,
  "title": "describe_operation_risk_serviceDictOutput"
}
🟢evaluate_operation_risk(source, tool, arguments)

Check whether the actual operation inside an MCP tool call is safe before execution. Use this when one MCP tool exposes multiple operations with different side effects, so whole-tool permissions are too coarse. Provide the native MCP server identity, the tool's tools/list metadata and the intended arguments. For supported consolidated tools, distinguish read, create/add, update/mutate and delete/destructive operations. Return ALLOW, DENY, or REQUIRE_APPROVAL. Unknown, unsupported, ambiguous, or schema-changed calls fail closed with REQUIRE_APPROVAL. The evaluator never executes the source operation.

Input Schema

{
  "type": "object",
  "properties": {
    "source": {
      "additionalProperties": false,
      "properties": {
        "server": {
          "additionalProperties": false,
          "properties": {
            "name": {
              "description": "Name reported by the MCP server during initialize; used as a supported-manifest lookup hint.",
              "title": "Name",
              "type": "string"
            },
            "version": {
              "anyOf": [
                {
                  "type": "string"
                },
                {
                  "type": "null"
                }
              ],
              "description": "Server version reported during initialize, or null when unavailable.",
              "title": "Version"
            }
          },
          "required": [
            "name",
            "version"
          ],
          "title": "NativeServerIdentity",
          "type": "object",
          "description": "MCP server identity from the connection's initialize response."
        },
        "protocol_version": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ],
          "description": "Negotiated MCP protocol version, or null when unavailable.",
          "title": "Protocol Version"
        }
      },
      "required": [
        "server",
        "protocol_version"
      ],
      "title": "NativeSource",
      "type": "object",
      "description": "MCP server and negotiated protocol identity for the source tool."
    },
    "tool": {
      "additionalProperties": false,
      "properties": {
        "name": {
          "description": "Exact tool name from the MCP server's tools/list response.",
          "title": "Name",
          "type": "string"
        },
        "title": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ],
          "default": null,
          "description": "Tool title from tools/list, when provided by the server.",
          "title": "Title"
        },
        "description": {
          "anyOf": [
            {
              "type": "string"
            },
            {
              "type": "null"
            }
          ],
          "description": "Tool description from tools/list, or null if the server omitted it.",
          "title": "Description"
        },
        "inputSchema": {
          "additionalProperties": true,
          "description": "Complete inputSchema from tools/list; used to validate the intended arguments and match a supported tool manifest.",
          "title": "Inputschema",
          "type": "object"
        },
        "annotations": {
          "additionalProperties": true,
          "description": "Tool annotations from tools/list, such as read-only or destructive hints; use an empty object when absent.",
          "title": "Annotations",
          "type": "object"
        },
        "execution": {
          "anyOf": [
            {
              "additionalProperties": true,
              "type": "object"
            },
            {
              "type": "null"
            }
          ],
          "default": null,
          "description": "Tool execution metadata from tools/list, when present.",
          "title": "Execution"
        },
        "outputSchema": {
          "anyOf": [
            {
              "additionalProperties": true,
              "type": "object"
            },
            {
              "type": "null"
            }
          ],
          "default": null,
          "description": "Tool output schema from tools/list, when present.",
          "title": "Outputschema"
        },
        "icons": {
          "anyOf": [
            {
              "items": {
                "additionalProperties": true,
                "type": "object"
              },
              "type": "array"
            },
            {
              "type": "null"
            }
          ],
          "default": null,
          "description": "Tool icons from tools/list, when present.",
          "title": "Icons"
        },
        "_meta": {
          "anyOf": [
            {
              "additionalProperties": true,
              "type": "object"
            },
            {
              "type": "null"
            }
          ],
          "default": null,
          "description": "Relevant tool metadata from tools/list, when present.",
          "title": "Meta"
        }
      },
      "required": [
        "name",
        "description",
        "inputSchema"
      ],
      "title": "NativeToolRecord",
      "type": "object",
      "description": "The complete relevant Tool record returned by the source server's tools/list."
    },
    "arguments": {
      "additionalProperties": true,
      "description": "Arguments intended for the source MCP tools/call request being evaluated. The evaluator does not execute that call.",
      "title": "Arguments",
      "type": "object"
    }
  },
  "required": [
    "source",
    "tool",
    "arguments"
  ],
  "additionalProperties": false,
  "title": "NativeMcpEvaluationRequest"
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded2 tools