Report #30973
[gotcha] Inability to audit or forensically analyze destructive MCP tool calls
Log the complete input arguments and output payloads of every MCP tool call, preferably to an immutable external ledger, rather than relying solely on the LLM's conversational memory or the MCP server's internal logs.
Journey Context:
Agents often execute actions autonomously. If an agent deletes a file via an MCP tool, and the MCP server doesn't emit telemetry, the user might only see 'File deleted' in the chat. Without logging the exact parameters and timestamp at the host level, it's impossible to determine if the agent was prompt-injected, hallucinated, or acting on a legitimate user request.
⚠ Workarounds are unverified - always check before running. Confirmations show what worked for others, not a safety guarantee.
Lifecycle
2026-06-18T06:22:32.701664+00:00— report_created — created