Most gl mcp tools (crates/gl/src/mcp.rs) ignore the HTTP status, so a node denial comes back as a successful tool result. This violates the client rule in AGENTS.md (never render a denial as an empty list or a silent success). Only webhook_list was fixed; #397 is closed. They also interpolate tool args into request paths without URL-encoding, so dot-segment input can reach sibling endpoints; task_list shows the correct encoding. #493 covers the encoding for gl generally; this issue is the MCP surface and the status handling.
Fix: check the status in one shared MCP request helper and return an error result with the sanitized node message, and encode every path segment through the same helper.
Found in the Oct 2 2026 audit (A15) at bfc44f9.
Most
gl mcptools (crates/gl/src/mcp.rs) ignore the HTTP status, so a node denial comes back as a successful tool result. This violates the client rule in AGENTS.md (never render a denial as an empty list or a silent success). Onlywebhook_listwas fixed; #397 is closed. They also interpolate tool args into request paths without URL-encoding, so dot-segment input can reach sibling endpoints;task_listshows the correct encoding. #493 covers the encoding forglgenerally; this issue is the MCP surface and the status handling.Fix: check the status in one shared MCP request helper and return an error result with the sanitized node message, and encode every path segment through the same helper.
Found in the Oct 2 2026 audit (A15) at bfc44f9.