MCP Spec Leaves Critical Gaps in AI Agent Tool-Call Audit Logging
The Model Context Protocol (MCP), now the standard way AI agents invoke external tools, includes almost no requirements for logging those tool calls, according to an analysis of its 2025-11-25 revision. While the spec mandates user consent before tool invocation, it does not define what evidence that consent record must contain or who should maintain it. The protocol's security best practices document mentions logging in only three narrow contexts — token passthrough, scope minimisation, and proxy stdio usage — leaving out any guidance on what a complete tool-call record should look like. Because most hosts store consent decisions in the same runtime-controlled transcript as all other model output, those records lack the independence needed to satisfy an external auditor. The result is that MCP deployments can show a tool was called but struggle to prove what the server actually did, or whether the user saw an accurate representation of the intended action.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in