MCP (Model Context Protocol) tools use annotation hints to communicate their security risk profile to organizations, including flags for destructive capabilities and open-world access; tools without configured hints default to conservative risk assumptions, while tools with explicit hints (like FastMail's email sending tool) provide clear indicators for security teams to make informed policy decisions about tool deployment.
Deep Dive
Prerequisite Knowledge
- No data available.
Where to go next
- No data available.
Deep Dive
Assessing MCP tool risk
Added:Hey, my name is Kai Hendry. I'm a consultant with ThoughtWorks.
And in my current role, I'm a security engineer helping to roll out MCPs in a large organization. So, if you're like me doing risk assessments with MCPs trying to work out what is the risk of rolling out uh Gmail MCP which essentially connects your cloud agent or whatever your agent you you use, your AI use with the potential of all that that that company data and email.
Likewise, Slack and whatever the Atlassian, whatever vendors the particular organization uses. So, let me show you the tool so you can better understand it that can help you do these security decisions, right?
So, for example, let's choose something innocuous like the AWS Docs MCP server.
Now, that doesn't have any hints set.
So, these annotation hints feed into your risk assessment or your your judgment call. And they don't have any set, so they're assumed to be quite conservative like they the tool can potentially be destructive potentially go open world and such and so forth. So, AWS Docs AWS Docs doesn't set these ones. But let me show you one that does.
For example, uh the FastMail one.
FastMail is an email provider that I use.
And the cool thing about the tool is that it's able to do the OAuth dance.
Ooh, I need to put in my password.
Here we go.
And now you see all the tools exposed by the Fast Mail MCP.
And for example, the the most controversial one is is perhaps sending email.
And you can see that the hints are kind of correctly set here. For example, open world hint. This is this is like the exfiltration path.
Hopefully you're familiar with the lethal tri factor. This is declared true. So, of course, if you had to make a judgment call about which tools to enable in as a policy in your company, this is perhaps how you would rank them like if they were if they were hinted like this. Of course, again, you must interpret them like for example, delete email is destructive hint false.
Which which is potentially arguable, but maybe it's it's declared false for a reason cuz it's able to that that risk.
So, anyway, this tool is called MCP hints.
Your comments, your likes, your stars would be much appreciated. Thank you.
Related Videos

Expanding Stikbot thumbnails
leopoldshorts
2K views•2023-09-24

Digital Discrimination: Cognitive Bias in Machine Learning
redmonktechevents2974
4K views•2019-12-18

Evolutionary Approach to Clustering by Ujjwal Maulik
ICTStalks
279 views•2019-06-26

Rose Yu "Learning from Large-Scale Spatiotemporal Data"
networkscienceinstitute
2K views•2019-03-04

Stanford Seminar - Generalization through Task Representations with Foundation Models
stanfordonline
4K views•2025-07-14

Satellite-Based Wheat Yield Forecasting using GEE & Transformer Neural Network
gisrsinstitute
634 views•2025-06-15

Paradigm Shifts in Data Processing for the Generative AI Era: Robert Nishihara of Anyscale & Ray.io
GradientFlow
2K views•2025-01-02

How to Build Your Own GenAI-Based Knowledge Management System
2150GmbH
360 views•2025-06-03
Trending

Playstation NO DISC/NO BUY Fight Is Over...
DavidJaffeGames
4K views•2026-07-23

Americans Confused in Australia for 17 Minutes Straight
IWrocker
17K views•2026-07-23

Bitcoin Social Interest: Dozens of us Left
benjaminjcowen
12K views•2026-07-23

Tesla Profits Plunge & SpaceX Stock Continues Fall
TheJohnJohnstonLounge
6K views•2026-07-23