← Files WebMCPARCHIVED FILE

skills/webmcp/references/security.md

1.56 KB · Oct 2, 2026 · 00:31 UTC

↓ Download file

# Security notes for WebMCP tools

Agents often inherit the **user’s cookies and logged-in session**. Treat every
tool as an authenticated capability.

## Author responsibilities

1. **Least privilege** — only register tools for actions the current user may
   perform; drop tools on logout.
2. **Honest annotations** — `readOnlyHint` / `untrustedContentHint` must match
   reality.
3. **No tool poisoning** — never put “system instructions”, secrets, or
   exfiltration hints in `name`, `title`, `description`, or parameter
   descriptions.
4. **Safe outputs** — sanitize or bound user-generated content in returns; set
   `untrustedContentHint: true` when in doubt.
5. **Validate in code** — do not trust `inputSchema` alone; reject bad input with
   clear errors.
6. **Confirm irreversible actions** — purchases, deletes, sends: require explicit
   parameters and/or in-page confirmation patterns your product already uses.

## Prompt injection vectors

| Vector | Mitigation |
| --- | --- |
| Malicious descriptions | You control metadata — keep it boring and accurate |
| Malicious tool output | Bound/sanitize; mark untrusted; avoid echoing raw HTML |
| Confused deputy via session | Server-side authz on every mutating path tools call |

## Cross-origin

- Default: tools are same-origin only
- Sharing into another frame requires `allow="tools"` + `exposedTo`
- Never expose privileged tools to origins you do not control

## What WebMCP does *not* replace

- Server authorization
- CSRF protections on cookie-authenticated APIs
- Human approval UX for high-risk actions

SHA-256: 8ee46cc2ac6979d022864ffee325911bc8ea889aab5a7284874555974872ac95