Ω Omega Protocol Bring us a question
OBSERVED

Artifact

mcp-boundary-audit

A harness detects a tool hidden from discovery yet reachable through the call surface, on a mock built to show it.

§ 1

What it establishes

That a harness can detect one authorization bug in Model Context Protocol servers. A tool hidden from tools/list yet reachable through tools/call, demonstrated on a mock server built to exhibit it.

§ 2

What it does not establish

Not a field measurement: the numbers come from an authored mock. It does not test HTTP or SSE transport, prompt injection, or token scope, and a PASS does not mean a server is secure.

§ 3

Method

The harness reads the advertised tool list, then probes whether the un-advertised tools are still callable; an unrecognised denial reads as inconclusive, never as a pass.

§ 4

Results

On the mock, 1 of 3 tools listed and 3 of 3 reachable, the 2 hidden tools callable, giving FAIL and exit 1; the patched server PASSes; 11 tests pass.

§ 5

What has to be trusted

The author's mock server, which defines both the vulnerable behaviour and the ground-truth tool set; a keyword-based denial heuristic that biases toward inconclusive, never toward a false FAIL.

§ 6

Prior work

Presentation-versus-execution authorization mismatches (CVE-2026-46519, GHSA-cr22-wjx7-2w6m). The contribution is the conservative harness that flags the reachable-but-hidden gap without false positives. A maintenance item tracks the 2026-07-28 MCP spec's stateless core (issue #1).

§ 7

Reproduce it

pip install -e '.[dev]' && cd examples && mcp-boundary-audit --config vulnerable_server.config.json --execute --i-own-this-server

Findings drawn from this artifact are on the evidence ledger.