ax-check rule

AXC-D011: openWorldHint false for a tool that reaches outside

openWorldHint is false while the name or first sentence mentions the web, a URL, email, a webhook or a third party.

ax-check is a checker being prepared for release. This page documents the rule ahead of that release; see all 50 rules.

Severitywarn
KindHeuristic. A pattern match: a prompt to look, not a verdict.
Modeax-check lint
Applies toMCP tool lists
Pattern tagsapproval, prompt-injection
Fix in one lineSet openWorldHint to true for tools that reach external systems, or reword the description if it does not.

The tool sets openWorldHint: false, which tells clients it works only inside a closed system, but its name or first sentence mentions the web, a URL, email, a webhook or a third party. A tool that reaches outside can send data out and bring untrusted text back in. Clients should be told.

What it checks

For each MCP tool that sets openWorldHint to false, ax-check looks for words that suggest contact with external systems in the tool’s name and the first sentence of its description.

Why it matters

The MCP schema defines openWorldHint as: the tool “may interact with an open world of external entities”, and gives an example: “a web search tool is open, a memory tool is not.” The default is true.

The difference matters for safety. A tool that fetches a web page or reads an inbox returns text written by someone else, and that text can contain instructions aimed at the agent. A tool that sends email or calls a webhook can leak data. A client that believes a tool is closed may apply less scrutiny to both directions. The specification also reminds clients to treat annotations as untrusted unless the server is trusted, so the hint helps only when it is honest.

How to fix

Set openWorldHint to true for tools that reach external systems. If the tool does not actually reach outside (for example, it only checks that an email address is well formed), reword the name or description so it does not suggest that it does.

Example

Before

{
  "name": "email_payment_reminder",
  "description": "Emails the customer a reminder for an overdue invoice. Use this when an invoice is more than 14 days overdue.",
  "annotations": {
    "readOnlyHint": false,
    "destructiveHint": false,
    "idempotentHint": false,
    "openWorldHint": false
  }
}

After

{
  "name": "email_payment_reminder",
  "description": "Emails the customer a reminder for an overdue invoice. Use this when an invoice is more than 14 days overdue.",
  "annotations": {
    "readOnlyHint": false,
    "destructiveHint": false,
    "idempotentHint": false,
    "openWorldHint": true
  }
}

How ax-check detects it

The rule runs only when openWorldHint is exactly false. ax-check turns underscores and hyphens in the name into spaces, then searches the name, and separately the first sentence of the description, ignoring case, for any of these terms: web, internet, website, webpage, web page, email, e-mail, emails, webhook, webhooks, third party, third-party, external API, external service, external system, external site, browse, crawl, scrape, SMS, Slack, tweet, “post to”. A URL counts only when a fetching verb comes before it, as in “fetch a URL”, “opens the given URL” or “calls https://…”. A tool that merely returns a URL, such as a link to a document, is not reported.

A match is ignored when one of the words no, not, never, without, nor or except appears in the 30 characters before it, with no full stop in between. So “Works without any external service” is not reported.

Known false positives: tools that handle external identifiers without contacting anything, such as validate_email, are reported. Reword the description or silence the rule with --disable AXC-D011.

Known false negatives: verbs such as “fetch”, “download” or “call” are not in the list on their own, so “Fetches the page at the given address” passes. Mentions after the first sentence are not read.

Sources

Records in the AX evidence register that share a pattern tag with this rule. A shared tag means the record is about the same pattern, not that it tests this rule. Read the evidence class before the number.