πΉ Go Fan Report: modelcontextprotocol/go-sdk
Selected by round-robin: most recently pushed direct dependency (pushed_at 2026-10-04T14:36:37Z, ahead of charmbracelet/x and cli/go-gh). First run of the round-robin β cache-memory state was empty, now seeded.
Module Overview
github.com/modelcontextprotocol/go-sdk is the official Go SDK for the Model Context Protocol, providing server primitives (mcp.NewServer/mcp.AddTool), client primitives (mcp.NewClient), and stdio/command/in-memory/streamable-HTTP transports.
Current Usage in gh-aw
- Version:
go.mod pins v1.8.0 β the latest release. Up to date, no action needed on the version itself.
- Files: 12 non-test
.go files (pkg/cli/mcp_*.go, pkg/parser/mcp.go)
- Key APIs used:
mcp.NewServer/mcp.AddTool with static tool-set capabilities (ListChanged: false), mcp.NewStreamableHTTPHandler (stateful, loopback-bound), AddReceivingMiddleware for schema-error rewriting, and on the client side mcp.NewClient + mcp.CommandTransport/mcp.StreamableClientTransport for gh aw mcp inspect β the one path that connects to arbitrary third-party/registry MCP servers.
Research Findings
Recent Updates (v1.8.0, 2026-09-14)
This release adds no new protocol revision; it hardens the 2026-07-28 support shipped in v1.7.0:
- Resource-exhaustion hardening:
SSEClientTransport/StreamableClientTransport gained MaxEventSize (default 16 MiB), StdioTransport/mcp.CommandTransport gained MaxLineLength (default bounded), and JSON decoding now rejects >1000 levels of nesting.
ServerOptions.SupportedProtocolVersions: lets a server narrow (never widen) which protocol versions it advertises/negotiates.
ServerOptions.SetCacheable: a hook that sets ttlMs/cacheScope on server/discover and */list results, after the handler runs.
- A stateful
StreamableHTTPHandler now returns a proper JSON-RPC error instead of a plain-text 400 for unsupported-revision requests, so clients can renegotiate down.
(v1.7.0's larger protocol-revision changes β stateless/sessionless mode, multi-round-trip requests, subscriptions/listen, x-mcp-header β were already reviewed previously and remain not applicable to gh-aw's current design.)
Best Practices Already Observed in gh-aw
mcp_server_http.go documents why Stateless stays false (session affinity for long-running logs/audit progress) and why the server binds to loopback only, as defense in depth alongside the SDK's own Host-header check.
mcp_tools_privileged.go documents why the timeout parameter deliberately has no static schema default.
mcp_inspect_mcp.go already sets DisableStandaloneSSE: true with a rationale comment β the same pattern this review suggests extending to the new v1.8.0 hardening knobs.
Improvement Opportunities
π Quick Wins
- Make the untrusted-peer transport bounds explicit in
pkg/cli/mcp_inspect_mcp.go (lines ~175 and ~208). This is the only code path where gh-aw's mcp.Client connects to a server it doesn't control (a registry's Command/Args or URL). The SDK's v1.8.0 defaults (16 MiB/event, bounded line length) already prevent unbounded memory growth β this isn't a vulnerability β but setting MaxEventSize/MaxLineLength explicitly, next to the existing DisableStandaloneSSE comment, would make the "these servers may be untrusted" intent self-documenting rather than resting on an upstream default.
β¨ Feature Opportunities
ServerOptions.SetCacheable: gh-aw's tool set is static (Tools.ListChanged: false, already documented in mcp_server.go). A SetCacheable hook marking tools/list/server/discover as long-TTL/public-cache would let conforming clients avoid re-fetching the tool list every session β a direct match for the existing "tools are static" rationale.
ServerOptions.SupportedProtocolVersions: could turn the implicit "we only really exercise 2025-11-25" assumption (since Stateless stays false) into an explicit, enforced one.
π Best Practice Alignment
Usage is idiomatic throughout: correct bare-bool annotation types (no hintomitempty=1 escape hatch needed), deliberate avoidance of premature schema defaults, and a strong convention of commenting why an SDK option is set a particular way. The only gap is that this commenting convention hasn't yet been extended to the v1.8.0 hardening options on the one untrusted-peer code path.
π§ General Improvements
None beyond the above β the dependency is already pinned to its latest release and the integration is deliberate and well-commented.
Recommendations
- No urgent action required this cycle.
- Low-effort: add explicit
MaxEventSize/MaxLineLength (even at SDK-default values, with a one-line rationale) to the mcp inspect client transports.
- Consider a
SetCacheable hook given the tool set is already documented as static.
- Keep
Stateless HTTP mode and SupportedProtocolVersions on the radar as the MCP ecosystem's stateful-session support evolves.
Next Steps
- No code change is required to stay current with upstream; the two feature/quick-win items above are optional hardening/clarity improvements for a future PR, not defects.
Generated by Go Fan
Module summary saved to: scratchpad/mods/go-sdk.md
Generated by πΉ Go Fan Β· claude Β· agent Β· 162.6 AIC Β· β 6.79 AIC Β· β 6.4K Β· β·
πΉ Go Fan Report: modelcontextprotocol/go-sdk
Selected by round-robin: most recently pushed direct dependency (
pushed_at2026-10-04T14:36:37Z, ahead ofcharmbracelet/xandcli/go-gh). First run of the round-robin β cache-memory state was empty, now seeded.Module Overview
github.com/modelcontextprotocol/go-sdkis the official Go SDK for the Model Context Protocol, providing server primitives (mcp.NewServer/mcp.AddTool), client primitives (mcp.NewClient), and stdio/command/in-memory/streamable-HTTP transports.Current Usage in gh-aw
go.modpins v1.8.0 β the latest release. Up to date, no action needed on the version itself..gofiles (pkg/cli/mcp_*.go,pkg/parser/mcp.go)mcp.NewServer/mcp.AddToolwith static tool-set capabilities (ListChanged: false),mcp.NewStreamableHTTPHandler(stateful, loopback-bound),AddReceivingMiddlewarefor schema-error rewriting, and on the client sidemcp.NewClient+mcp.CommandTransport/mcp.StreamableClientTransportforgh aw mcp inspectβ the one path that connects to arbitrary third-party/registry MCP servers.Research Findings
Recent Updates (v1.8.0, 2026-09-14)
This release adds no new protocol revision; it hardens the
2026-07-28support shipped in v1.7.0:SSEClientTransport/StreamableClientTransportgainedMaxEventSize(default 16 MiB),StdioTransport/mcp.CommandTransportgainedMaxLineLength(default bounded), and JSON decoding now rejects >1000 levels of nesting.ServerOptions.SupportedProtocolVersions: lets a server narrow (never widen) which protocol versions it advertises/negotiates.ServerOptions.SetCacheable: a hook that setsttlMs/cacheScopeonserver/discoverand*/listresults, after the handler runs.StreamableHTTPHandlernow returns a proper JSON-RPC error instead of a plain-text 400 for unsupported-revision requests, so clients can renegotiate down.(v1.7.0's larger protocol-revision changes β stateless/sessionless mode, multi-round-trip requests,
subscriptions/listen,x-mcp-headerβ were already reviewed previously and remain not applicable to gh-aw's current design.)Best Practices Already Observed in gh-aw
mcp_server_http.godocuments whyStatelessstaysfalse(session affinity for long-runninglogs/auditprogress) and why the server binds to loopback only, as defense in depth alongside the SDK's own Host-header check.mcp_tools_privileged.godocuments why thetimeoutparameter deliberately has no static schema default.mcp_inspect_mcp.goalready setsDisableStandaloneSSE: truewith a rationale comment β the same pattern this review suggests extending to the new v1.8.0 hardening knobs.Improvement Opportunities
π Quick Wins
pkg/cli/mcp_inspect_mcp.go(lines ~175 and ~208). This is the only code path where gh-aw'smcp.Clientconnects to a server it doesn't control (a registry'sCommand/ArgsorURL). The SDK's v1.8.0 defaults (16 MiB/event, bounded line length) already prevent unbounded memory growth β this isn't a vulnerability β but settingMaxEventSize/MaxLineLengthexplicitly, next to the existingDisableStandaloneSSEcomment, would make the "these servers may be untrusted" intent self-documenting rather than resting on an upstream default.β¨ Feature Opportunities
ServerOptions.SetCacheable: gh-aw's tool set is static (Tools.ListChanged: false, already documented inmcp_server.go). ASetCacheablehook markingtools/list/server/discoveras long-TTL/public-cache would let conforming clients avoid re-fetching the tool list every session β a direct match for the existing "tools are static" rationale.ServerOptions.SupportedProtocolVersions: could turn the implicit "we only really exercise2025-11-25" assumption (sinceStatelessstaysfalse) into an explicit, enforced one.π Best Practice Alignment
Usage is idiomatic throughout: correct bare-
boolannotation types (nohintomitempty=1escape hatch needed), deliberate avoidance of premature schema defaults, and a strong convention of commenting why an SDK option is set a particular way. The only gap is that this commenting convention hasn't yet been extended to the v1.8.0 hardening options on the one untrusted-peer code path.π§ General Improvements
None beyond the above β the dependency is already pinned to its latest release and the integration is deliberate and well-commented.
Recommendations
MaxEventSize/MaxLineLength(even at SDK-default values, with a one-line rationale) to themcp inspectclient transports.SetCacheablehook given the tool set is already documented as static.StatelessHTTP mode andSupportedProtocolVersionson the radar as the MCP ecosystem's stateful-session support evolves.Next Steps
Generated by Go Fan
Module summary saved to:
scratchpad/mods/go-sdk.md