MCP spec: tool annotations are untrusted. What that means for Sume

The MCP spec says clients must treat tool annotations as untrusted unless they come from a trusted server. Treat Sume as trusted only for your own workspace.

5 min readSume
All posts

The 2025-11-25 MCP specification says clients must consider tool annotations untrusted unless they come from a trusted server. In practice that means a client may show readOnlyHint to a person, but it should not let that hint alone skip an approval for a tool that spends money. For Sume, the safer reading is that the annotation is a convenience and the credential is the real gate.

Where the real gate sits

The enforcement lives on the Sume side. Under an OAuth session that has only mcp:read, write tools are not in the list, and calling one by name returns insufficient_scope. A model cannot talk its way past that, and a wrong annotation cannot widen it.

Spec guidance (read 2026-10-09) next to how Sume gates calls (as of 2026-10-09)
ConcernSpec saysSume does
AnnotationsUntrusted unless from a trusted serverTools carry read-only hints, but scope does not depend on them
ConfirmationClients SHOULD prompt for confirmation on sensitive operationsWrite calls hidden under mcp:read; need mcp:write or an API key
LoggingClients SHOULD log tool usageWrite and paid calls need an idempotency_key you can log
ErrorsTool errors use isError trueScope failures return insufficient_scope with required_scope mcp:write

Settings that follow from this

Sume's max_spend_usd and dry_run are optional and apply only when sent, so they are a habit to teach the agent, not a guarantee. A client approval prompt on paid tools is the control that does not depend on the model.

  • Auto-approve only tools you have checked in the Sume tool list, not everything with a read-only hint.
  • Prefer OAuth with Write off for sessions that only browse models, jobs and balances.
  • Keep paid tools on manual approval, and send max_spend_usd so a call has a ceiling.
  • Log the idempotency_key and job id for every write call so a retry can be told apart from a new spend.

When trust is reasonable

You connect to https://mcp.sume.com/mcp with your own credential, so the server is yours to trust at the scope you granted. That is different from a third-party server you found in a directory, where a hint could be wrong or hostile. Even for Sume, trust follows the credential: an API key means the full surface, and an OAuth session means the scopes you ticked.

A short test for your client

Connect with an OAuth session that has Write off, then ask the model to submit a paid job. You should see no write tool in the list, and a direct call by name should fail with insufficient_scope. Repeat with an API key and a paid tool and confirm that your client still asks you before it runs. If it does not ask, the client is trusting an annotation or an auto-approve rule, and that is the setting to change.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume