Host principles (2026-07-28): user consent and control (users explicitly consent to and understand all data access and operations), data privacy (explicit consent before exposing user data to servers; no passing resource data elsewhere without consent), and tool safety (tools are arbitrary code execution; get explicit consent before invoking any tool). Earlier revisions also listed sampling controls; Sampling is now deprecated.
Human in the loop: there SHOULD always be a human able to deny tool invocations. Hosts SHOULD show which tools are exposed, indicate when they run, and confirm sensitive operations.
Annotations are hints. readOnlyHint (default false), destructiveHint (default true), idempotentHint (default false), openWorldHint (default true). Clients MUST treat them as untrusted unless they come from a trusted server, and should never base tool-use decisions on annotations from untrusted servers.
Prompt injection and tool poisoning. The core spec doesn't define these terms; the widely used definition (Invariant Labs, 2025) is malicious instructions hidden in tool descriptions or results, visible to the model but not the user. Related: a rug pull, where a tool's definition changes after approval. The spec's defences: show inputs before calling, validate results before passing them to the model, sanitize outputs, and confirm sensitive operations.
Audit and observability. Clients SHOULD log tool usage for audit. Trace context travels in _meta as traceparent, tracestate and baggage (W3C formats). OpenTelemetry's MCP conventions (in development) name spans {mcp.method.name} {target} with attributes such as mcp.method.name, gen_ai.tool.name and error.type (tool_error when isError is true). clientInfo and serverInfo are self-reported: never use them for security decisions.