Ω Omega Protocol Bring us a question
OBSERVED

Finding · execute

Tools removed from the list an agent is shown were still there to call by name.

§ 1

The record

FINDING · tools-hidden-from-discovery-remain-callableexecute · observation boundary
Tools removed from the list an agent is shown were still there to call by name.
Claim
In a server built to exhibit the bug, tools filtered from the discovery listing remained reachable through the call surface: a presentation-layer authorization control with no execution-layer enforcement behind it.
Status
OBSERVED Witnessed in one instance. No claim about how often.
Question
Authorised is not executed
Subject
A mock MCP server built to exhibit the bug (authored). built for the study
Frame
stdio transport only; no HTTP, prompt injection or token scope.
Method
Read the advertised tool list, then probe whether un-advertised tools are still callable; an unrecognised denial reads as inconclusive.
Oracle
The call surface: whether tools/call succeeds for a tool absent from tools/list.
Negative control
Present The patched server passes; the vulnerable server fails with exit 1.
Denominator
1 of 3 tools listed, 3 of 3 reachable, on the mock.
Limitation
This is a demonstration against an authored mock, not a measurement of real servers. It does not test HTTP transport, prompt injection, or token scope, and a passing result does not mean a server is secure.
Source
repowazdogz-droid/mcp-boundary-audit @ d932934f
Reproduce
pip install -e '.[dev]' && cd examples && mcp-boundary-audit --config vulnerable_server.config.json --execute --i-own-this-server
Independent reproduction
None known.
§ 2

Where this sits

This finding answers Authorised is not executed and supports the EXECUTE stage of the operating method. It is an instance of the observation boundary mechanism.

Evidence ledgerBring us a problem