Tool Annotations as Risk Vocabulary: What Hints Can and Can't Do
4.40T1 sourceModel Context Protocol Blog
Source record
Published by Model Context Protocol Blog (T1 source). The original is at https://blog.modelcontextprotocol.io/posts/2026-03-16-tool-annotations/.
Pipeline notes
The summary and note below are generated by the signal pipeline — they are Beyond Desk’s reading, not quotations from the source.
SummaryThe MCP blog reviews tool annotations (read-only, destructive, idempotent, side-effecting) introduced roughly a year ago, summarizes their current state, and offers a framework for evaluating five community-filed Specification Enhancement Proposals for new annotations.
Why it mattersFrom the protocol maintainers themselves: a shared risk vocabulary is a precondition for safer agentic workflows, and the proposed evaluation framework is directly applicable to anyone building on MCP.

Cited by
No citations on record.
