Python: Add models for the MCP server SDKs (mcp, fastmcp) - #22703
Open
Alex-Hofer wants to merge 1 commit into
Open
Alex-Hofer wants to merge 1 commit into
Alex-Hofer wants to merge 1 commit into
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Implements the proposal in #22702. The observation there about
py/xxe,py/xml-bombandpy/nosql-injectiontaking onlyRemoteFlowSourceis separate and not changed by this PR.MCP servers expose tools to LLM agents. Every parameter of a tool, resource or prompt handler is
chosen by the client, that is by a model that prompt injection can steer, or by anyone who can
reach the server over HTTP. This PR models that input for the two Python SDKs as sources of the
remotethreat model, as Models-as-Data next to the existingStdlib.model.ymlsources.Covered:
mcp1.xFastMCPand 2.xMCPServer:tool(),resource(),prompt(),add_tool(fn).Server: the 1.x decoratorscall_tool(),read_resource(),get_prompt(), andthe 2.x constructor handlers
on_call_tool,on_read_resource,on_get_prompt, whereparams.arguments/params.uriis the source.fastmcp2.x to 4.x:toolandpromptbare, called or as a plain call,resource(),add_tool,add_prompt,Tool.from_function,fastmcp.tools.tool, the transport headers viaget_http_headers()andget_http_request().headers.Authorizationheader, inverify_tokenofTokenVerifier(and
AuthProvider) subclasses and fromget_access_token().token.typeModelrows for the re-exported import paths of the classes.Tests:
library-tests/frameworks/mcpandlibrary-tests/frameworks/fastmcpuseMaDTest(
mad-source__remote); every row has a handler with an inline expectation, and classes with thesame method name but no SDK base class have none.
Evidence: with these rows (as a model pack) CodeQL 2.27.1 finds 13 of 28 real, publicly disclosed
MCP server vulnerabilities in mcp-vulnbench
instead of 1; on the half of the cases that was held out while writing the rows, 9 of 16 instead
of 0, at 0.27 to 1.09 alarms per KLOC. Known limits of this form (handlers behind project
decorators, Pydantic-typed parameters, headers read through the
Contextobject) are documentedthere and in the issue.