From 5962a10d420d80c23af06729423f72841ec7d8fa Mon Sep 17 00:00:00 2001 From: Exploit Intel Date: Thu, 10 Sep 2026 20:30:56 +0300 Subject: [PATCH] Pin mcp below the release that masks validator refusals Every refusal this server words for itself is raised from a Pydantic WrapValidator: the bounds, the enum listings, the whole-number distinction. mcp 2.1.0 stopped propagating anything raised during argument validation, so all of it reaches the caller as the bare "Error executing tool ". The SDK's own docstring for the wrapper says nothing from the original reaches the client. Bisected against a minimal probe rather than assumed: 2.0.0 and 2.0.1 keep the message, 2.1.0, 2.1.1 and 2.2.0 mask it. The declared range was >=2.0.0,<3, so a fresh install from PyPI has been resolving to a masked build since 2.1.0 shipped, while ovh2 stayed correct only because it happened to install 2.0.0. This restores the suite to 1970 passing. Lifting the pin needs the refusals moved out of validators into the tool bodies, where a ToolError message still survives on every version tested. --- pyproject.toml | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/pyproject.toml b/pyproject.toml index 020dae2..c8bdc6c 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -17,7 +17,12 @@ classifiers = [ "Topic :: Security", ] dependencies = [ - "mcp>=2.0.0,<3", + # 2.1.0 stopped propagating messages raised during argument validation: + # anything a Pydantic validator raises reaches the caller as the bare + # "Error executing tool ", losing every refusal this server words for + # itself. Bisected 2.0.1 good, 2.1.0 bad. Lifting this needs the refusals + # moved out of validators into the tool bodies, where messages still survive. + "mcp>=2.0.0,<2.1", "httpx2>=2.5.0,<3", ]