Skip to content

Security Checklist

When to Use

Run through this before exposing Tool API tools to any non-human caller. Each item links to the page that owns the rule.

Version: applies to drupal/tool 1.0.0-beta11 (beta; no security advisory coverage), tool_belt 1.0.0-alpha6, mcp_server_tool_bridge 1.0.0-beta3.

Checklist

Common Mistakes

  • Trusting operation: Read to mean safe → nothing enforces it; review the code

See Also

  • Access Control
  • OWASP API Security Top 10: https://owasp.org/API-Security/