From 51aaceec76a0cafbc11bbfb87b40bd0b72c44a02 Mon Sep 17 00:00:00 2001 From: Arsalan Shahid Date: Mon, 21 Sep 2026 13:52:57 +0100 Subject: [PATCH] MCP: audit.submit_to_scitt is annotated read-only, as the coordinator now has it #153 moved audit.submit_to_scitt into the coordinator's read-only set, because recording the submission appended to the chain being submitted. readOnlyHint is defined as exactly that set, so the annotation had to move with it, and annotations.test.ts said so. The Python table is generated from the TypeScript one, so both change together. openWorldHint still carries the fact that the call reaches a service outside this coordinator: read-only here, open-world there. --- packages/coordinator-mcp/src/tools.ts | 4 ++++ .../coordinator-py/chap_coordinator/transports/mcp_tools.py | 2 +- 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/packages/coordinator-mcp/src/tools.ts b/packages/coordinator-mcp/src/tools.ts index b1c31a3..c62c04b 100644 --- a/packages/coordinator-mcp/src/tools.ts +++ b/packages/coordinator-mcp/src/tools.ts @@ -271,6 +271,10 @@ export interface ToolAnnotations { */ const READ_ONLY = new Set([ "chap.workspace.describe", "chap.audit.read", "chap.audit.verify_chain", "chap.audit.verify_receipt", + // Submitting reads the chain and sends it onward. It changes nothing here, + // which is what readOnlyHint claims; openWorldHint carries the fact that it + // reaches a service outside this coordinator. + "chap.audit.submit_to_scitt", ]); /** Overwrites, removes, or settles state irreversibly. */ diff --git a/packages/coordinator-py/chap_coordinator/transports/mcp_tools.py b/packages/coordinator-py/chap_coordinator/transports/mcp_tools.py index 1fa3b74..ffccdc0 100644 --- a/packages/coordinator-py/chap_coordinator/transports/mcp_tools.py +++ b/packages/coordinator-py/chap_coordinator/transports/mcp_tools.py @@ -356,7 +356,7 @@ }, "chap.audit.submit_to_scitt": { "title": "Anchor audit log in SCITT", - "readOnlyHint": False, + "readOnlyHint": True, "destructiveHint": False, "idempotentHint": False, "openWorldHint": True,