Skip to content

Extend defined goals of MCP Problem type - #1772

Open
guidorc wants to merge 5 commits into
mcp-action-builderfrom
feature/mcp-fuzzing-goals
Open

guidorc wants to merge 5 commits into
mcp-action-builderfrom
feature/mcp-fuzzing-goals

Conversation

@guidorc

@guidorc guidorc commented Sep 16, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Expandind the MCP black-box fitness analysis, adding schema-based action generation, richer coverage objectives, and fault detection.

Changes

  • Builds executable MCP tool actions from each tool’s JSON Schema inputSchema.
  • Adds coverage objectives for:
  1. Tools and resources reached.
  2. Successful and failed tool calls.
  3. Distinct JSON-RPC outcomes.
  4. Resources found or not found.
  5. Non-empty resource content.
  • Detects MCP-specific faults:
  1. Tool internal errors (-32603).
  2. Advertised resources that return resource-not-found (-32002).
  3. Successful tool results whose structuredContent does not conform to the declared outputSchema.
  • Preserves protocol-level JSON-RPC errors in MCP result DTOs and reports detected faults through McpCallResult.

Implementation

HttpMcpClient now parses:

  • Tool outputSchema declarations.
  • Tool structuredContent as Jackson JsonNode.
  • JSON-RPC protocol errors for tool calls and resource reads.

Declared output schemas are compiled once during MCP discovery with networknt’s JSON Schema 2020-12 validator and cached by tool name. Successful tool responses are then validated against the cached schema. Each distinct violation produces a stable SCHEMA_INVALID_RESPONSE fitness target and a detected fault.

External schema references are disabled by default to prevent schemas from initiating network or file requests. They can be enabled explicitly with:

--allowExternalSchemaReferences=true

@guidorc
guidorc marked this pull request as ready for review September 27, 2026 21:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant