microsoft / microsoft/simplechat

MCP Track B Phase B4: add guarded personal chat write tool

Open
#1,019 1 comment 0 reactions 1 assignee View on GitHub

@Bionic711 is already working on this.

Since Jul 9, 2026.

enhancement security_improvement
Dominant language
Python
Stars
152
Forks
116
Avg merge
7h 7m
Merged PRs (30d)
122

Description

## Summary

Add `send_personal_chat_message` to the inbound SimpleChat MCP server only after read-only personal tools, auth, governance, telemetry, and tests are stable.

## Scope

- Add `send_personal_chat_message` as a personal-scope-only inbound MCP tool.
- Require a valid delegated user identity.
- Validate conversation ownership/access when `conversation_id` is supplied.
- Define behavior for new-conversation creation.
- Preserve content safety behavior.
- Preserve model invocation and token/cost logging.
- Add rate limits and abuse protections.
- Bound response size.
- Add audit events that identify caller app, user, tool, conversation, and success/failure without logging message secrets.

## Acceptance Criteria

- [ ] Tool is disabled unless explicitly allowed by inbound MCP governance.
- [ ] Tool cannot target group/public/all-scope contexts.
- [ ] Existing conversation writes require ownership or valid access.
- [ ] New conversation creation behavior is explicit and tested.
- [ ] Content safety and model logging behavior is preserved.
- [ ] Rate limits and bounded responses are enforced.
- [ ] Tests cover new conversation creation, existing conversation ownership validation, rejection for inaccessible conversations, rate-limit behavior, bounded response behavior, and audit logging redaction.

## Notes

Parent: #1013
Depends on the inbound auth/governance foundation and read-only personal tools issues.
Planning doc: `docs/explanation/features/MCP_PLUGIN_ROBUSTNESS_PLAN.md`
Priority: P1
Size: L

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.