Files
jhonny-editor/code/docs/recommendations/2026-08-18/08-artifact-resource-links.md
T
João Henrique b541f502ba feat: initial commit - Jhonny Editor
- Adicionado estrutura completa do projeto
- Configurado MCP server para Premiere Pro
- Adicionado documentação e skills
- Configurado Gitignore para o projeto
2026-09-08 09:59:31 -04:00

26 lines
1.1 KiB
Markdown
Executable File

# Recommendation 08: contained artifact resource links
## Evidence
MCP tool results can return resource links and embedded resources. Export, AAF, and
compatibility reports currently describe paths in ordinary result data, which is
hard for clients to consume safely.
- [MCP tool result content](https://modelcontextprotocol.io/specification/2026-07-28/server/tools)
- [MCP resource security](https://modelcontextprotocol.io/specification/2026-07-28/server/resources)
## Proposed improvement
Create authorization-scoped artifact IDs and expose only registered, size-bounded
files under a dedicated URI scheme. Canonicalize paths, reject links/reparse points,
set short expirations, and never turn an arbitrary tool-supplied path into a resource.
## Acceptance
- Export/report results include a resource link only after artifact registration.
- Traversal, alternate separators, symlinks, oversized files, and expired IDs fail closed.
- Resource reads recheck authorization and MIME type.
- Existing text and structured results remain available to older clients.
Artifact existence still requires post-export verification.