Security Checklist
When to Use
Run through this before exposing Tool API tools to any non-human caller. Each item links to the page that owns the rule.
Version: applies to
drupal/tool1.0.0-beta11 (beta; no security advisory coverage),tool_belt1.0.0-alpha6,mcp_server_tool_bridge1.0.0-beta3.
Checklist
- [ ] Every tool declares a
permissionfor account-level rules and usescheckAccess()for object-level rules (OWASP API1, broken object level authorization) → Access Control - [ ]
checkAccess()passes the given$accountto every entity and field access call → Access Control - [ ] Invokers you write call
checkPermission()before setting inputs, andvalidateInputs()beforeaccess()→ Calling a Tool from PHP - [ ] MCP-exposed tools keep refiners and input transforms free of side effects, because the bridge sets inputs before any denial → Calling a Tool over MCP
- [ ] Failure messages and failure
context_valuescarry no internals → doExecute and ExecutableResult - [ ] No undeclared result keys carry entities or secrets → Output Definitions
- [ ] Write tools validate the entity before saving;
tool_belt:entity_savedoes not → Tool Belt Catalog - [ ]
operationanddestructiveare honest, and agent tool lists exclude destructive tools → Operation and Destructive, Calling a Tool from the AI Module - [ ] Prerequisites that must block are re-checked in
doExecute()→ checkRequirements - [ ] Access rules are tested with a role-scoped
--uid, not uid 1 → Calling a Tool from Drush - [ ]
administer toolstays on trusted roles → Installation and Submodules
Common Mistakes
- Trusting
operation: Readto mean safe → nothing enforces it; review the code
See Also
- Access Control
- OWASP API Security Top 10: https://owasp.org/API-Security/