Approve MCP tool calls on purpose

A connected server is not a blank cheque. Read the tool name and args before you click allow.

Most clients prompt on the first write, or on every tool if you set it that way. The prompt is the review. Do not train yourself to hit always-allow.

Read-only list or get is usually safe to allow for a session. delete, send, deploy, pay, and shell need a second look at the path or payload.

If the tool list is huge, uninstall servers you are not using this hour. You cannot review what you cannot see.

See MCP security basics and when-not-to-use-MCP. A listing here is not an audit of those tools.