modelcontextprotocol / modelcontextprotocol/python-sdk
FastMCP tool argument models silently ignore unknown/misspelled arguments (extra=ignore default)
还没有人认领这个 Issue。
- 主要语言
- Python
- 星标
- 24.3k
- 派生
- 4k
- 平均合并
- 1 天 1 小时
- 30 天内合并 PR
- 31
描述
Description
mcp.server.fastmcp.utilities.func_metadata.ArgModelBase does not set extra in its
model_config, so it inherits Pydantic v2's default, extra="ignore":
class ArgModelBase(BaseModel):
"""A model representing the arguments to a function."""
...
model_config = ConfigDict(
arbitrary_types_allowed=True,
)
Every per-tool *Arguments model that FastMCP generates via create_model(..., __base__=ArgModelBase, ...)
inherits this. As a result, when a client calls a tool with an argument name that doesn't
exist on the function (a typo, or a hallucinated parameter name from an LLM), Pydantic
silently drops it instead of raising a validation error. The tool then runs with that
parameter at its default value, and returns a "successful" but semantically wrong result —
with no signal anywhere that anything was off.
Reproduction
from mcp.server.fastmcp import FastMCP
mcp = FastMCP("repro")
@mcp.tool()
def read_doc(topic: str = "") -> str:
return f"topic={topic!r}"
# Simulate what happens when a client calls with the wrong argument name:
tool = mcp._tool_manager.get_tool("read_doc")
result = tool.fn_metadata.arg_model.model_validate({"path": "something"})
print(result.model_dump_one_level())
# {'topic': ''} <- no error, no signal that "path" was bogus
Expected behavior
An unknown argument in a tools/call request should fail validation immediately with a
clear error (e.g. Pydantic's own "Extra inputs are not permitted"), the same way a missing
required argument already does. This is especially important for MCP given the primary
caller is frequently an LLM: a wrong parameter name is a common, plausible failure mode, and
a loud, immediate error is far more useful (and self-correcting for the model) than a
silently-wrong "successful" response.
Suggested fix
Set extra="forbid" on ArgModelBase.model_config:
model_config = ConfigDict(
arbitrary_types_allowed=True,
extra="forbid",
)
This should be safe: the fields validated by ArgModelBase subclasses are exactly the
arguments dict of a tools/call request (i.e. exactly what's declared in the tool's
inputSchema). Protocol-level fields (_meta, progressToken, etc.) live on the
surrounding params object, not inside arguments, and Context is injected separately
via arguments_to_pass_directly — neither passes through ArgModelBase. The side effect is
that model_json_schema() will now emit "additionalProperties": false on the published
inputSchema, which seems like a feature, not a regression (it lets clients that validate
against the schema catch this class of error before the round-trip).
Scope checked
- Confirmed present in
mcp1.27.2 and 1.28.1 (latest on PyPI as of 2026-07). - Confirmed still present on
main(the in-progress v2, wherefastmcpis being renamed to
mcpserver):src/mcp/server/mcpserver/utilities/func_metadata.pyhas the same
ArgModelBasewithoutextraset. - I didn't find an existing issue about this specific behavior (searched for "extra fields",
"forbid", "unknown argument", "additionalProperties", "silently ignored"). - For context: the TypeScript SDK has an equivalent gap for a different underlying reason
(Zod's defaultstripbehavior on unknown object keys) — see
https://github.com/modelcontextprotocol/typescript-sdk/issues/147
Happy to open a PR with the one-line change plus a regression test if that's useful.
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
从 src/mcp/server/mcpserver/utilities/func_metadata.py 开始,检查 ArgModelBase.model_config 以及生成的 arg_model 验证路径。添加一个使用 read_doc-style 未知参数案例的回归测试,然后运行相关的 FastMCP 测试;当未知工具参数引发验证错误且发布的 schema 拒绝额外属性时,即表示完成。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- python
- 领域
- api, backend-api-design
- Issue 类型
- 缺陷
- 难度
- 2/5
- 预计耗时
- 1-3 小时
- 活跃度
- 冷清
- 描述清晰度
- 描述清楚
- 新手友好度
- 76/100