AE-HCGDFGC3
Invalid MCP require_approval policies silently normalize to no approval, exposing tools without human-in-the-loop
AUTHORITY ERRORseverity: HIGHcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: HIGH
MCPServer._normalize_needs_approval turned a misspelled string policy into False, ignored a misspelled per-tool mapping value, and let never override always for a tool listed in both. A user could believe approval was enabled while the SDK exposed the MCP tool without approval.
- Framework / agent
- OpenAI Agents SDK (Python) · tool-calling agent using MCP servers
- Remediation attempts
- TESTED
- Recurrence
- not documented
- Source languages
- en
- Updated
- 2026-09-30
Sources
- GITHUB ISSUE MCP require_approval invalid values can fail open — github.com/openai/openai-agents-python, retrieved 2026-09-29
- GITHUB PULL REQUEST fix: #3168 validate MCP require_approval policies — github.com/openai/openai-agents-python, retrieved 2026-09-29
Symptoms
- A typo such as "alwyas" in require_approval yields a policy that requires no approval
- A tool listed in both always and never tool_names ends up not requiring approval
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-HCGDFGC3. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.