Repository navigation
Add tool annotations to server-fetch (1 tool, 0 annotated) #3572
Description
Activity
I opened a PR for this on current
main.Scope is fetch-only (no time/everything changes):
ToolAnnotationson thefetchtool per the table in this issue, plus a short README annotation table matching the filesystem server docs.Local gate:
cd src/fetch && uv run pytest -q cd src/fetch && uv run ruff check src tests- addedenhancementNew feature or requestNew feature or requestserver-fetchReference implementation for the Fetch MCP server - src/fetchReference implementation for the Fetch MCP server - src/fetch
on Oct 10, 2026 Picked up for v1.0.0 (#5080): Copilot flagged the missing annotations on the release PR #5090, and
AGENTS.mdrequires them on every tool that changes (fetchchanged in this milestone, #1624, #4838). The values are the ones proposed here (readOnlyHint: true,destructiveHint: false,idempotentHint: true,openWorldHint: true), fixed onv2/mainand on the release branch. Thanks to @olaservo for the request, and to @nielskaspers (#3580), @Chelebii (#3876) and @piyushbag (#4428) for the PRs that proposed the same change; under this repository's contribution policy those PRs will be closed with a pointer here once the fix merges.- linked a pull request that will close this issuefix(fetch): annotate the fetch tool #5112
on Oct 10, 2026 - linked a pull request that will close this issuev1.0.0: annotate the fetch tool (release branch) #5113
on Oct 10, 2026 - added a commit that references this issue
on Oct 11, 2026
Request: Add tool annotations —
@modelcontextprotocol/server-fetchContext
The fetch server currently provides zero annotations on its 1 tool. For reference,
@modelcontextprotocol/server-filesystemannotates all 14 of its tools withreadOnlyHint,destructiveHint, andidempotentHint. We're requesting the same treatment here.Current state — 0/1 tools annotated
readOnlyHintdestructiveHintidempotentHintopenWorldHintfetchSuggested annotations
readOnlyHintdestructiveHintidempotentHintopenWorldHintfetchtruefalsetruetrueRationale
fetch→readOnlyHint: true,idempotentHint: true,openWorldHint: trueThis tool fetches a URL via HTTP GET and returns the content as markdown. It does not modify any data on the target server or locally. It is idempotent — fetching the same URL twice returns the same result (modulo server-side changes). It is open-world because it makes outbound HTTP requests to arbitrary URLs on the internet.
openWorldHint: trueis particularly important here. The fetch tool can reach any URL, making it a key vector in multi-server setups where an agent could chain a read from a local tool (e.g.read_graphfrom the memory server) into an outbound fetch to exfiltrate data. Accurate annotations help clients enforce "allow reads, gate sends" policies.Impact
This is a ~5 line metadata addition to the single tool registration. No behavior changes. The
server-filesystemalready sets the precedent for annotation coverage across reference servers.