ax-check rule

AXC-F007: Served MCP tool is not mentioned

The live server serves a tool that none of the checked files mention.

ax-check is a checker being prepared for release. This page documents the rule ahead of that release; see all 50 rules.

Severityinfo
KindObserved. Depends on the program and environment at run time.
Modeax-check drift
Applies toInstruction files and manifests
Pattern tagsdrift, discovery
Fix in one lineMention the tool where agents read about this server, or remove it if it should not be served.

The live MCP server returns a tool that none of the files you checked mention. This is the mirror image of AXC-F006. It is only information, because a server may serve tools that are meant to be found through the tool list alone.

What it checks

When you pass --mcp <url> (your explicit request for that connection), ax-check fetches tools/list from the server (an initialize call followed by tools/list, both read-only). It then compares the served tool names with the tool names found in all the files you gave it. The rule fires for each served tool that appears in none of them.

Why it matters

An agent usually learns about a server’s tools from the tool list. But the files around the server often carry the context that the list cannot: when to prefer one tool to another, which one needs approval, which one is new. A tool that is served but never explained is a tool the instructions cannot help the agent choose. It can also be a sign that a tool was added and nobody updated the docs, or that a tool was left on the server that was meant to be removed.

The finding is info for that reason. It asks you to decide, not to repair.

How to fix

  • Mention the tool where agents read about this server, with a sentence on when to use it and when to use its neighbour instead. The guide on writing tool descriptions explains how.
  • Or remove the tool from the server, if it should not be there.
  • Or silence the rule, if the tool list is the intended single source of truth.

Example

Find it:

ax-check drift --mcp https://mcp.example.com/mcp AGENTS.md SKILL.md

Before

# AGENTS.md

## Invoice tools

- `invoice_create`: draft a new invoice.
- `list_invoices`: find existing invoices.

The server also serves invoice_void, which cancels an invoice and is not mentioned in either file.

After

# AGENTS.md

## Invoice tools

- `invoice_create`: draft a new invoice.
- `list_invoices`: find existing invoices.
- `invoice_void`: cancel an unpaid invoice. Ask the user first. Do not use it to correct a typo; create a new invoice instead.

How ax-check detects it

The extraction and the rule logic are deterministic, but the result depends on what the live server returns from tools/list at the time of the run, so the same file can give different findings on another day. JSON and SARIF reports record when and where the check ran. It builds one set of claimed tool names from every file in the run, using the same extraction as AXC-F006: backticked snake_case identifiers on a line or under a heading that mentions “tool” or “tools”, and tool names in JSON tools lists. It then subtracts those from the served list.

Because the comparison is across all files, pass every file that documents the server. A tool mentioned in a file you did not pass looks undocumented.

Known limits:

  • A tool mentioned in prose without backticks, or outside a line or heading that mentions “tool”, does not count as mentioned.
  • Claims are only read for snake_case names, so a served tool whose name has no underscore may be reported even when a file documents it. Silence the rule if that applies.

If you do not pass --mcp, this rule does not run. To silence it, use --disable AXC-F007.

Sources

Records in the AX evidence register that share a pattern tag with this rule. A shared tag means the record is about the same pattern, not that it tests this rule. Read the evidence class before the number.

  • EV-0013: FAQ blocks and structured data showed no citation effect within a domain (Preprint). An observational study of about 2 million AI-engine citations (preprint) found that FAQ blocks, structured data and Core Web Vitals had positive effects on citation in pooled data that reversed or fell to zero once domain fixed effects were applied.
  • EV-0019: Skill selection precision collapses as the skill pool grows (Preprint). A preprint reports that as the pool of available skills grew from 5 to 100, the precision with which agents actually used the right skill fell from 29.6% to 3.3%.
  • EV-0023: Hiding tools is not enforcing permissions (Preprint). Across 2,160 attempts with four frontier models (preprint), a server with only in-body permission checks exposed forbidden tools in 152 of 720 trials and permission-aware visibility cut that to 0 of 720, yet models named a hidden tool in up to 94% of settings when it was inferable from the prompt.
  • EV-0027: A capable agent skipped the index and guessed the page (Preprint). A preregistered ablation on a 709-page Markdown wiki (preprint) found that a capable tool-using agent never loaded the compact catalogue index, inferring page paths from the question instead, while retrieval-based access kept answer quality non-inferior and cut cost by about a third to over half.
  • EV-0039: Launch post and documentation disagree on agent output format (Independent measurement). Cloudflare's cf launch post says JSON output is 'condensed for agents', but the cf documentation says JSON output is indented whether or not output is a terminal, and a public issue reports byte-identical output with an agent detected.
  • EV-0040: Agent skills recommended a package that does not exist (Vendor measurement). Merged pull requests in Vercel's agent plugin repository corrected skill instructions that recommended an npm package that is not published, and plugin guidance that advertised deployment cards the production MCP server does not expose.