ax-check rule
AXC-D011: openWorldHint false for a tool that reaches outside
openWorldHint is false while the name or first sentence mentions the web, a URL, email, a webhook or a third party.
ax-check is a checker being prepared for release. This page documents the rule ahead of that release; see all 50 rules.
| Severity | warn |
| Kind | Heuristic. A pattern match: a prompt to look, not a verdict. |
| Mode | ax-check lint |
| Applies to | MCP tool lists |
| Pattern tags | approval, prompt-injection |
| Fix in one line | Set openWorldHint to true for tools that reach external systems, or reword the description if it does not. |
The tool sets openWorldHint: false, which tells clients it works only inside a closed system, but its name or first sentence mentions the web, a URL, email, a webhook or a third party. A tool that reaches outside can send data out and bring untrusted text back in. Clients should be told.
What it checks
For each MCP tool that sets openWorldHint to false, ax-check looks for words that suggest contact with external systems in the tool’s name and the first sentence of its description.
Why it matters
The MCP schema defines openWorldHint as: the tool “may interact with an open world of external entities”, and gives an example: “a web search tool is open, a memory tool is not.” The default is true.
The difference matters for safety. A tool that fetches a web page or reads an inbox returns text written by someone else, and that text can contain instructions aimed at the agent. A tool that sends email or calls a webhook can leak data. A client that believes a tool is closed may apply less scrutiny to both directions. The specification also reminds clients to treat annotations as untrusted unless the server is trusted, so the hint helps only when it is honest.
How to fix
Set openWorldHint to true for tools that reach external systems. If the tool does not actually reach outside (for example, it only checks that an email address is well formed), reword the name or description so it does not suggest that it does.
Example
Before
{
"name": "email_payment_reminder",
"description": "Emails the customer a reminder for an overdue invoice. Use this when an invoice is more than 14 days overdue.",
"annotations": {
"readOnlyHint": false,
"destructiveHint": false,
"idempotentHint": false,
"openWorldHint": false
}
}
After
{
"name": "email_payment_reminder",
"description": "Emails the customer a reminder for an overdue invoice. Use this when an invoice is more than 14 days overdue.",
"annotations": {
"readOnlyHint": false,
"destructiveHint": false,
"idempotentHint": false,
"openWorldHint": true
}
}
How ax-check detects it
The rule runs only when openWorldHint is exactly false. ax-check turns underscores and hyphens in the name into spaces, then searches the name, and separately the first sentence of the description, ignoring case, for any of these terms: web, internet, website, webpage, web page, email, e-mail, emails, webhook, webhooks, third party, third-party, external API, external service, external system, external site, browse, crawl, scrape, SMS, Slack, tweet, “post to”. A URL counts only when a fetching verb comes before it, as in “fetch a URL”, “opens the given URL” or “calls https://…”. A tool that merely returns a URL, such as a link to a document, is not reported.
A match is ignored when one of the words no, not, never, without, nor or except appears in the 30 characters before it, with no full stop in between. So “Works without any external service” is not reported.
Known false positives: tools that handle external identifiers without contacting anything, such as validate_email, are reported. Reword the description or silence the rule with --disable AXC-D011.
Known false negatives: verbs such as “fetch”, “download” or “call” are not in the list on their own, so “Fetches the page at the given address” passes. Mentions after the first sentence are not read.
Sources
- Specification: Model Context Protocol schema reference, ToolAnnotations, revision 2026-07-28. https://modelcontextprotocol.io/specification/2026-07-28/schema . Defines
openWorldHint(“a web search tool is open, a memory tool is not”), default true. - Specification: Tools, Model Context Protocol specification, revision 2026-07-28. https://modelcontextprotocol.io/specification/2026-07-28/server/tools . Says clients “MUST consider tool annotations to be untrusted unless they come from trusted servers.”
- Site guide: Write tool descriptions an agent can act on, agentexperience.tech. https://agentexperience.tech/insights/tool-descriptions/ . Recommends writing the boundary in the description and enforcing it in the server, because annotations are untrusted.
Related evidence
Records in the AX evidence register that share a pattern tag with this rule. A shared tag means the record is about the same pattern, not that it tests this rule. Read the evidence class before the number.
- EV-0015: Approvals that outlive their task raise attack success (Preprint). A preprint reports that approvals persisted beyond the context that justified them raised prompt-injection attack success by up to 35.1 percentage points on 508 AgentDojo cases, and by 24.9 points on average in live tests on three production coding agents.
- EV-0014: Allow/ask/never policies blocked less overreach than per-action approval (Preprint). In a study of 113 people without software backgrounds (preprint), user-authored allow/ask/never policies blocked 20.1 percentage points less agent overreach than per-action approval, partly because participants chose 'ask' for 114 of 140 rules and then approved most overreach at runtime.
- EV-0016: Approval records omit the effects a command goes on to trigger (Preprint). A preprint reports that coding-agent approval records name the approved command but omit effects its workflow exercises: across 111 approval and trace pairs, unrecorded residual effects fell from 40 with explicit fields to 17 with command semantics and 13 with decision-time metadata.
- EV-0026: Prompt injection split across tool channels evades defences (Preprint). Across 12 frontier models and over 15,000 trials (preprint), models that resisted single-channel prompt injection exfiltrated data at up to 100% when the payload was split across two channels, such as a tool description and a tool result, and seven third-party MCP security tools failed to detect it.
- EV-0034: Vendor claim: users approved about 93% of permission prompts (Vendor claim). Anthropic states that its telemetry showed users approved roughly 93% of Claude Code permission prompts, and that an operating-system sandbox reduced permission prompts by 84%.
