CyberMax
Home › Glossary › MCP and AI agents

What are MCP tool annotations?

MCP and AI agents glossary · 1 primary source

Optional hints on an MCP tool that describe its behaviour: readOnlyHint, destructiveHint, idempotentHint and openWorldHint.

readOnlyHint: true says the tool does not change anything; destructiveHint says whether updates can be destructive; idempotentHint says repeating the same call has no extra effect; openWorldHint says the tool reaches outside systems such as the web. Clients can use them to decide when to ask for confirmation.

They are hints, not guarantees: the specification says clients must treat annotations as untrusted unless they come from a trusted server.

Example: "annotations": {"readOnlyHint": true, "openWorldHint": true, "idempotentHint": true, "destructiveHint": false}

Real example

The annotations published by our Kevscope MCP server's tools/list:

ToolAnnotations
cve_priorityreadOnlyHint=true, openWorldHint=true, idempotentHint=true, destructiveHint=false
kev_recentreadOnlyHint=true, openWorldHint=true, idempotentHint=true, destructiveHint=false
epss_watchlistreadOnlyHint=true, openWorldHint=true, idempotentHint=true, destructiveHint=false

Kevscope MCP server docs

Sources

Related terms

On this site

All mcp and ai agents terms · Full glossary