Skip to content

Schema generation pipeline may produce overly permissive schemas without safeguards #2600

Description

@httpsVishu

What's broken?

The JSON schema is wrong (incorrect type, constraint, or field)

Where in the spec or docs?

https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/scripts/generate-schemas.ts

What should happen?

i was exploring scripts/generate-schemas.ts and noticed something around how schemas are generated and finalized
the schema generation pipeline should ensure that generated json schemas enforce reasonable validation boundaries by default or at least validate the final output for overly permissive structures

at minimum, the pipeline should detect and flag overly permissive schemas before they are committed

What actually happens?

right now schemas are generated using

npx typescript-json-schema --defaultNumberType integer --required --skipLibCheck "${schemaTs}" "*"

and is then modified via string-based transformations after which they are written directly without any validation or constraint enforcement

since the final schema fully depends on how typescript types are defined, no additional safeguards are applied during generation and schemas may allow loosely structured or arbitrary inputs

hence, the pipeline can produce overly permissive schemas without any indication or warning

Anything else?

this is not an immediate runtime bug in this repository but more of a design gap in the schema generation pipeline

just wanted to understand whether this level of permissiveness is intentional (for flexibility) or an oversight in the current generation process

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions