Artifact
mcp-boundary-audit
A harness detects a tool hidden from discovery yet reachable through the call surface, on a mock built to show it.
What it establishes
That a harness can detect one authorization bug in Model Context Protocol servers. A tool hidden from tools/list yet reachable through tools/call, demonstrated on a mock server built to exhibit it.
What it does not establish
Not a field measurement: the numbers come from an authored mock. It does not test HTTP or SSE transport, prompt injection, or token scope, and a PASS does not mean a server is secure.
Method
The harness reads the advertised tool list, then probes whether the un-advertised tools are still callable; an unrecognised denial reads as inconclusive, never as a pass.
Results
On the mock, 1 of 3 tools listed and 3 of 3 reachable, the 2 hidden tools callable, giving FAIL and exit 1; the patched server PASSes; 11 tests pass.
What has to be trusted
The author's mock server, which defines both the vulnerable behaviour and the ground-truth tool set; a keyword-based denial heuristic that biases toward inconclusive, never toward a false FAIL.
Prior work
Presentation-versus-execution authorization mismatches (CVE-2026-46519, GHSA-cr22-wjx7-2w6m). The contribution is the conservative harness that flags the reachable-but-hidden gap without false positives. A maintenance item tracks the 2026-07-28 MCP spec's stateless core (issue #1).
Reproduce it
pip install -e '.[dev]' && cd examples && mcp-boundary-audit --config vulnerable_server.config.json --execute --i-own-this-server
Findings drawn from this artifact are on the evidence ledger.