Skip to content

[go-fan] Go Module Review: modelcontextprotocol/go-sdkΒ #65810

Description

@github-actions

🐹 Go Fan Report: modelcontextprotocol/go-sdk

Selected by round-robin: most recently pushed direct dependency (pushed_at 2026-10-04T14:36:37Z, ahead of charmbracelet/x and cli/go-gh). First run of the round-robin β€” cache-memory state was empty, now seeded.

Module Overview

github.com/modelcontextprotocol/go-sdk is the official Go SDK for the Model Context Protocol, providing server primitives (mcp.NewServer/mcp.AddTool), client primitives (mcp.NewClient), and stdio/command/in-memory/streamable-HTTP transports.

Current Usage in gh-aw

  • Version: go.mod pins v1.8.0 β€” the latest release. Up to date, no action needed on the version itself.
  • Files: 12 non-test .go files (pkg/cli/mcp_*.go, pkg/parser/mcp.go)
  • Key APIs used: mcp.NewServer/mcp.AddTool with static tool-set capabilities (ListChanged: false), mcp.NewStreamableHTTPHandler (stateful, loopback-bound), AddReceivingMiddleware for schema-error rewriting, and on the client side mcp.NewClient + mcp.CommandTransport/mcp.StreamableClientTransport for gh aw mcp inspect β€” the one path that connects to arbitrary third-party/registry MCP servers.

Research Findings

Recent Updates (v1.8.0, 2026-09-14)

This release adds no new protocol revision; it hardens the 2026-07-28 support shipped in v1.7.0:

  • Resource-exhaustion hardening: SSEClientTransport/StreamableClientTransport gained MaxEventSize (default 16 MiB), StdioTransport/mcp.CommandTransport gained MaxLineLength (default bounded), and JSON decoding now rejects >1000 levels of nesting.
  • ServerOptions.SupportedProtocolVersions: lets a server narrow (never widen) which protocol versions it advertises/negotiates.
  • ServerOptions.SetCacheable: a hook that sets ttlMs/cacheScope on server/discover and */list results, after the handler runs.
  • A stateful StreamableHTTPHandler now returns a proper JSON-RPC error instead of a plain-text 400 for unsupported-revision requests, so clients can renegotiate down.

(v1.7.0's larger protocol-revision changes β€” stateless/sessionless mode, multi-round-trip requests, subscriptions/listen, x-mcp-header β€” were already reviewed previously and remain not applicable to gh-aw's current design.)

Best Practices Already Observed in gh-aw

  • mcp_server_http.go documents why Stateless stays false (session affinity for long-running logs/audit progress) and why the server binds to loopback only, as defense in depth alongside the SDK's own Host-header check.
  • mcp_tools_privileged.go documents why the timeout parameter deliberately has no static schema default.
  • mcp_inspect_mcp.go already sets DisableStandaloneSSE: true with a rationale comment β€” the same pattern this review suggests extending to the new v1.8.0 hardening knobs.

Improvement Opportunities

πŸƒ Quick Wins

  • Make the untrusted-peer transport bounds explicit in pkg/cli/mcp_inspect_mcp.go (lines ~175 and ~208). This is the only code path where gh-aw's mcp.Client connects to a server it doesn't control (a registry's Command/Args or URL). The SDK's v1.8.0 defaults (16 MiB/event, bounded line length) already prevent unbounded memory growth β€” this isn't a vulnerability β€” but setting MaxEventSize/MaxLineLength explicitly, next to the existing DisableStandaloneSSE comment, would make the "these servers may be untrusted" intent self-documenting rather than resting on an upstream default.

✨ Feature Opportunities

  • ServerOptions.SetCacheable: gh-aw's tool set is static (Tools.ListChanged: false, already documented in mcp_server.go). A SetCacheable hook marking tools/list/server/discover as long-TTL/public-cache would let conforming clients avoid re-fetching the tool list every session β€” a direct match for the existing "tools are static" rationale.
  • ServerOptions.SupportedProtocolVersions: could turn the implicit "we only really exercise 2025-11-25" assumption (since Stateless stays false) into an explicit, enforced one.

πŸ“ Best Practice Alignment

Usage is idiomatic throughout: correct bare-bool annotation types (no hintomitempty=1 escape hatch needed), deliberate avoidance of premature schema defaults, and a strong convention of commenting why an SDK option is set a particular way. The only gap is that this commenting convention hasn't yet been extended to the v1.8.0 hardening options on the one untrusted-peer code path.

πŸ”§ General Improvements

None beyond the above β€” the dependency is already pinned to its latest release and the integration is deliberate and well-commented.

Recommendations

  1. No urgent action required this cycle.
  2. Low-effort: add explicit MaxEventSize/MaxLineLength (even at SDK-default values, with a one-line rationale) to the mcp inspect client transports.
  3. Consider a SetCacheable hook given the tool set is already documented as static.
  4. Keep Stateless HTTP mode and SupportedProtocolVersions on the radar as the MCP ecosystem's stateful-session support evolves.

Next Steps

  • No code change is required to stay current with upstream; the two feature/quick-win items above are optional hardening/clarity improvements for a future PR, not defects.

Generated by Go Fan
Module summary saved to: scratchpad/mods/go-sdk.md

Generated by 🐹 Go Fan Β· claude Β· agent Β· 162.6 AIC Β· βŒ– 6.79 AIC Β· ⊞ 6.4K Β· β—·

  • expires on Oct 6, 2026, 12:15 AM UTC-08:00

Activity

  1. github-actions commented on Oct 6, 2026

    @github-actions
    ContributorAuthor

    This issue was automatically closed because it expired on 2026-10-06T08:15:30.457Z.

    Closed by Workflow

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions