Skip to content

feat(bigquery): add native read-only session locking - #3851

Merged
anubhav756 merged 1 commit into
feat/read-onlyfrom
anubhav-readonly-bigquery
Aug 27, 2026
Merged

anubhav756 merged 1 commit into
feat/read-onlyfrom
anubhav-readonly-bigquery

Conversation

@anubhav756

@anubhav756 anubhav756 commented Aug 20, 2026 •

Copy link
Copy Markdown
Contributor

Overview

Add support for BigQuery in Toolbox's Read-Only architecture.

When BigQuery is configured with writeMode: "blocked", the source is recognized as read-only (IsReadOnly() == true). bigquery-execute-sql remains available to AI agents for SELECT queries as a single polymorphic tool, dynamically updating its MCP annotations to readOnlyHint: true and destructiveHint: false. Any dedicated mutating tools without read-only annotations are automatically suppressed.

Changes

  • Updated BigQuerySource.IsReadOnly() to return true when WriteMode == "blocked".
  • Added unit tests covering all writeMode states (blocked, allowed, protected, empty default).
  • Implemented ShouldSuppress(ctx, source) bool { return false } so execute_sql remains exposed to agents for SELECT queries on read-only sources.
  • Implemented GetAnnotations(src) to dynamically return readOnlyHint: true and destructiveHint: false when connected to a writeMode: "blocked" source, preserving custom hints.
  • Added comprehensive unit tests (TestGetAnnotations, TestShouldSuppress).
  • Exposed writeMode: ${BIGQUERY_WRITE_MODE:allowed} on bigquery-source so prebuilt images can be launched in read-only mode via environment variables (BIGQUERY_WRITE_MODE=blocked ./toolbox --prebuilt bigquery).
  • Added TestBigQuery_ReadOnlyVulnerabilityBlock verifying that if a custom tool is falsely annotated with readOnlyHint: true on a writeMode: "blocked" source, BigQuery dry-run validation catches and rejects mutating SQL statements (like CREATE TABLE) before execution.
  • Updated the writeMode reference table to document coordination with MCP read-only annotations and tool suppression.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the IsReadOnly method in the BigQuery source implementation to dynamically check if the write mode is blocked (WriteModeBlocked), rather than unconditionally returning false. It also adds a comprehensive unit test suite TestBigQuerySource_IsReadOnly to verify this behavior across various write modes. There are no review comments, and I have no additional feedback to provide.

@anubhav756
anubhav756 force-pushed the anubhav-readonly-bigquery branch 2 times, most recently from 8e805ce to c8c0a29 Compare August 20, 2026 17:50
@anubhav756
anubhav756 force-pushed the anubhav-readonly-cloudsqlmysql branch from 5cf614a to c71c091 Compare August 21, 2026 05:32
@anubhav756
anubhav756 force-pushed the anubhav-readonly-bigquery branch 5 times, most recently from 84a5f99 to 3eaf4eb Compare August 21, 2026 11:11
@anubhav756
anubhav756 marked this pull request as ready for review August 21, 2026 12:04
@anubhav756
anubhav756 requested review from a team as code owners August 21, 2026 12:04
@anubhav756
anubhav756 changed the base branch from anubhav-readonly-cloudsqlmysql to anubhav-readonly-annotation August 21, 2026 12:04
@anubhav756 anubhav756 assigned Yuan325 and unassigned duwenxin99 Aug 21, 2026
@anubhav756
anubhav756 force-pushed the anubhav-readonly-bigquery branch 2 times, most recently from 697eff4 to 778cc1e Compare August 21, 2026 12:27
Comment thread internal/prebuiltconfigs/tools/bigquery.yaml Outdated
Comment thread docs/en/integrations/bigquery/tools/bigquery-execute-sql.md Outdated
Comment thread internal/sources/bigquery/bigquery.go
@anubhav756
anubhav756 force-pushed the anubhav-readonly-bigquery branch from 778cc1e to 3b2e01c Compare August 24, 2026 10:15
@Yuan325 Yuan325 added the priority: p1 Important issue which blocks shipping the next release. Will be fixed prior to next release. label Aug 25, 2026
@anubhav756
anubhav756 force-pushed the anubhav-readonly-bigquery branch from 3b2e01c to 76039a3 Compare August 25, 2026 06:22
@anubhav756
anubhav756 force-pushed the anubhav-readonly-annotation branch from adf943c to e6f7564 Compare August 26, 2026 21:06
@anubhav756
anubhav756 force-pushed the anubhav-readonly-bigquery branch from e3ad29a to 3faf198 Compare August 26, 2026 21:33
@anubhav756
anubhav756 force-pushed the anubhav-readonly-bigquery branch from 3faf198 to ff01292 Compare August 27, 2026 06:11
@anubhav756
anubhav756 force-pushed the anubhav-readonly-annotation branch 2 times, most recently from a96d2ab to 0a4a063 Compare August 27, 2026 06:48
Base automatically changed from anubhav-readonly-annotation to feat/read-only August 27, 2026 06:49
@anubhav756
anubhav756 force-pushed the anubhav-readonly-bigquery branch from ff01292 to a65f735 Compare August 27, 2026 06:52
@anubhav756
anubhav756 merged commit 86f922b into feat/read-only Aug 27, 2026
21 of 23 checks passed
@anubhav756
anubhav756 deleted the anubhav-readonly-bigquery branch August 27, 2026 06:53
@github-actions

Copy link
Copy Markdown
Contributor

🧨 Preview deployments removed.

Cloudflare Pages environments for pr-3851 have been deleted.

anubhav756 added a commit that referenced this pull request Aug 27, 2026
## Overview
Add support for BigQuery in Toolbox's Read-Only architecture.

When BigQuery is configured with `writeMode: "blocked"`, the source is
recognized as read-only (`IsReadOnly() == true`). `bigquery-execute-sql`
remains available to AI agents for `SELECT` queries as a single
polymorphic tool, dynamically updating its MCP annotations to
`readOnlyHint: true` and `destructiveHint: false`. Any dedicated
mutating tools without read-only annotations are automatically
suppressed.

## Changes

- Updated `BigQuerySource.IsReadOnly()` to return `true` when `WriteMode
== "blocked"`.
- Added unit tests covering all `writeMode` states (`blocked`,
`allowed`, `protected`, empty default).
- Implemented `ShouldSuppress(ctx, source) bool { return false }` so
`execute_sql` remains exposed to agents for `SELECT` queries on
read-only sources.
- Implemented `GetAnnotations(src)` to dynamically return `readOnlyHint:
true` and `destructiveHint: false` when connected to a `writeMode:
"blocked"` source, preserving custom hints.
- Added comprehensive unit tests (`TestGetAnnotations`,
`TestShouldSuppress`).
- Exposed `writeMode: ${BIGQUERY_WRITE_MODE:allowed}` on
`bigquery-source` so prebuilt images can be launched in read-only mode
via environment variables (`BIGQUERY_WRITE_MODE=blocked ./toolbox
--prebuilt bigquery`).
- Added `TestBigQuery_ReadOnlyVulnerabilityBlock` verifying that if a
custom tool is falsely annotated with `readOnlyHint: true` on a
`writeMode: "blocked"` source, BigQuery dry-run validation catches and
rejects mutating SQL statements (like `CREATE TABLE`) before execution.
- Updated the `writeMode` reference table to document coordination with
MCP read-only annotations and tool suppression.
anubhav756 added a commit that referenced this pull request Aug 27, 2026
## Overview
Add support for BigQuery in Toolbox's Read-Only architecture.

When BigQuery is configured with `writeMode: "blocked"`, the source is
recognized as read-only (`IsReadOnly() == true`). `bigquery-execute-sql`
remains available to AI agents for `SELECT` queries as a single
polymorphic tool, dynamically updating its MCP annotations to
`readOnlyHint: true` and `destructiveHint: false`. Any dedicated
mutating tools without read-only annotations are automatically
suppressed.

## Changes

- Updated `BigQuerySource.IsReadOnly()` to return `true` when `WriteMode
== "blocked"`.
- Added unit tests covering all `writeMode` states (`blocked`,
`allowed`, `protected`, empty default).
- Implemented `ShouldSuppress(ctx, source) bool { return false }` so
`execute_sql` remains exposed to agents for `SELECT` queries on
read-only sources.
- Implemented `GetAnnotations(src)` to dynamically return `readOnlyHint:
true` and `destructiveHint: false` when connected to a `writeMode:
"blocked"` source, preserving custom hints.
- Added comprehensive unit tests (`TestGetAnnotations`,
`TestShouldSuppress`).
- Exposed `writeMode: ${BIGQUERY_WRITE_MODE:allowed}` on
`bigquery-source` so prebuilt images can be launched in read-only mode
via environment variables (`BIGQUERY_WRITE_MODE=blocked ./toolbox
--prebuilt bigquery`).
- Added `TestBigQuery_ReadOnlyVulnerabilityBlock` verifying that if a
custom tool is falsely annotated with `readOnlyHint: true` on a
`writeMode: "blocked"` source, BigQuery dry-run validation catches and
rejects mutating SQL statements (like `CREATE TABLE`) before execution.
- Updated the `writeMode` reference table to document coordination with
MCP read-only annotations and tool suppression.
anubhav756 added a commit that referenced this pull request Aug 27, 2026
## Overview
Add support for BigQuery in Toolbox's Read-Only architecture.

When BigQuery is configured with `writeMode: "blocked"`, the source is
recognized as read-only (`IsReadOnly() == true`). `bigquery-execute-sql`
remains available to AI agents for `SELECT` queries as a single
polymorphic tool, dynamically updating its MCP annotations to
`readOnlyHint: true` and `destructiveHint: false`. Any dedicated
mutating tools without read-only annotations are automatically
suppressed.

## Changes

- Updated `BigQuerySource.IsReadOnly()` to return `true` when `WriteMode
== "blocked"`.
- Added unit tests covering all `writeMode` states (`blocked`,
`allowed`, `protected`, empty default).
- Implemented `ShouldSuppress(ctx, source) bool { return false }` so
`execute_sql` remains exposed to agents for `SELECT` queries on
read-only sources.
- Implemented `GetAnnotations(src)` to dynamically return `readOnlyHint:
true` and `destructiveHint: false` when connected to a `writeMode:
"blocked"` source, preserving custom hints.
- Added comprehensive unit tests (`TestGetAnnotations`,
`TestShouldSuppress`).
- Exposed `writeMode: ${BIGQUERY_WRITE_MODE:allowed}` on
`bigquery-source` so prebuilt images can be launched in read-only mode
via environment variables (`BIGQUERY_WRITE_MODE=blocked ./toolbox
--prebuilt bigquery`).
- Added `TestBigQuery_ReadOnlyVulnerabilityBlock` verifying that if a
custom tool is falsely annotated with `readOnlyHint: true` on a
`writeMode: "blocked"` source, BigQuery dry-run validation catches and
rejects mutating SQL statements (like `CREATE TABLE`) before execution.
- Updated the `writeMode` reference table to document coordination with
MCP read-only annotations and tool suppression.
anubhav756 added a commit that referenced this pull request Aug 27, 2026
## Overview
Add support for BigQuery in Toolbox's Read-Only architecture.

When BigQuery is configured with `writeMode: "blocked"`, the source is
recognized as read-only (`IsReadOnly() == true`). `bigquery-execute-sql`
remains available to AI agents for `SELECT` queries as a single
polymorphic tool, dynamically updating its MCP annotations to
`readOnlyHint: true` and `destructiveHint: false`. Any dedicated
mutating tools without read-only annotations are automatically
suppressed.

## Changes

- Updated `BigQuerySource.IsReadOnly()` to return `true` when `WriteMode
== "blocked"`.
- Added unit tests covering all `writeMode` states (`blocked`,
`allowed`, `protected`, empty default).
- Implemented `ShouldSuppress(ctx, source) bool { return false }` so
`execute_sql` remains exposed to agents for `SELECT` queries on
read-only sources.
- Implemented `GetAnnotations(src)` to dynamically return `readOnlyHint:
true` and `destructiveHint: false` when connected to a `writeMode:
"blocked"` source, preserving custom hints.
- Added comprehensive unit tests (`TestGetAnnotations`,
`TestShouldSuppress`).
- Exposed `writeMode: ${BIGQUERY_WRITE_MODE:allowed}` on
`bigquery-source` so prebuilt images can be launched in read-only mode
via environment variables (`BIGQUERY_WRITE_MODE=blocked ./toolbox
--prebuilt bigquery`).
- Added `TestBigQuery_ReadOnlyVulnerabilityBlock` verifying that if a
custom tool is falsely annotated with `readOnlyHint: true` on a
`writeMode: "blocked"` source, BigQuery dry-run validation catches and
rejects mutating SQL statements (like `CREATE TABLE`) before execution.
- Updated the `writeMode` reference table to document coordination with
MCP read-only annotations and tool suppression.
anubhav756 added a commit that referenced this pull request Aug 27, 2026
## Overview
Add support for BigQuery in Toolbox's Read-Only architecture.

When BigQuery is configured with `writeMode: "blocked"`, the source is
recognized as read-only (`IsReadOnly() == true`). `bigquery-execute-sql`
remains available to AI agents for `SELECT` queries as a single
polymorphic tool, dynamically updating its MCP annotations to
`readOnlyHint: true` and `destructiveHint: false`. Any dedicated
mutating tools without read-only annotations are automatically
suppressed.

## Changes

- Updated `BigQuerySource.IsReadOnly()` to return `true` when `WriteMode
== "blocked"`.
- Added unit tests covering all `writeMode` states (`blocked`,
`allowed`, `protected`, empty default).
- Implemented `ShouldSuppress(ctx, source) bool { return false }` so
`execute_sql` remains exposed to agents for `SELECT` queries on
read-only sources.
- Implemented `GetAnnotations(src)` to dynamically return `readOnlyHint:
true` and `destructiveHint: false` when connected to a `writeMode:
"blocked"` source, preserving custom hints.
- Added comprehensive unit tests (`TestGetAnnotations`,
`TestShouldSuppress`).
- Exposed `writeMode: ${BIGQUERY_WRITE_MODE:allowed}` on
`bigquery-source` so prebuilt images can be launched in read-only mode
via environment variables (`BIGQUERY_WRITE_MODE=blocked ./toolbox
--prebuilt bigquery`).
- Added `TestBigQuery_ReadOnlyVulnerabilityBlock` verifying that if a
custom tool is falsely annotated with `readOnlyHint: true` on a
`writeMode: "blocked"` source, BigQuery dry-run validation catches and
rejects mutating SQL statements (like `CREATE TABLE`) before execution.
- Updated the `writeMode` reference table to document coordination with
MCP read-only annotations and tool suppression.
anubhav756 added a commit that referenced this pull request Aug 27, 2026
## Overview
Add support for BigQuery in Toolbox's Read-Only architecture.

When BigQuery is configured with `writeMode: "blocked"`, the source is
recognized as read-only (`IsReadOnly() == true`). `bigquery-execute-sql`
remains available to AI agents for `SELECT` queries as a single
polymorphic tool, dynamically updating its MCP annotations to
`readOnlyHint: true` and `destructiveHint: false`. Any dedicated
mutating tools without read-only annotations are automatically
suppressed.

## Changes

- Updated `BigQuerySource.IsReadOnly()` to return `true` when `WriteMode
== "blocked"`.
- Added unit tests covering all `writeMode` states (`blocked`,
`allowed`, `protected`, empty default).
- Implemented `ShouldSuppress(ctx, source) bool { return false }` so
`execute_sql` remains exposed to agents for `SELECT` queries on
read-only sources.
- Implemented `GetAnnotations(src)` to dynamically return `readOnlyHint:
true` and `destructiveHint: false` when connected to a `writeMode:
"blocked"` source, preserving custom hints.
- Added comprehensive unit tests (`TestGetAnnotations`,
`TestShouldSuppress`).
- Exposed `writeMode: ${BIGQUERY_WRITE_MODE:allowed}` on
`bigquery-source` so prebuilt images can be launched in read-only mode
via environment variables (`BIGQUERY_WRITE_MODE=blocked ./toolbox
--prebuilt bigquery`).
- Added `TestBigQuery_ReadOnlyVulnerabilityBlock` verifying that if a
custom tool is falsely annotated with `readOnlyHint: true` on a
`writeMode: "blocked"` source, BigQuery dry-run validation catches and
rejects mutating SQL statements (like `CREATE TABLE`) before execution.
- Updated the `writeMode` reference table to document coordination with
MCP read-only annotations and tool suppression.
anubhav756 added a commit that referenced this pull request Aug 27, 2026
## Overview
Add support for BigQuery in Toolbox's Read-Only architecture.

When BigQuery is configured with `writeMode: "blocked"`, the source is
recognized as read-only (`IsReadOnly() == true`). `bigquery-execute-sql`
remains available to AI agents for `SELECT` queries as a single
polymorphic tool, dynamically updating its MCP annotations to
`readOnlyHint: true` and `destructiveHint: false`. Any dedicated
mutating tools without read-only annotations are automatically
suppressed.

## Changes

- Updated `BigQuerySource.IsReadOnly()` to return `true` when `WriteMode
== "blocked"`.
- Added unit tests covering all `writeMode` states (`blocked`,
`allowed`, `protected`, empty default).
- Implemented `ShouldSuppress(ctx, source) bool { return false }` so
`execute_sql` remains exposed to agents for `SELECT` queries on
read-only sources.
- Implemented `GetAnnotations(src)` to dynamically return `readOnlyHint:
true` and `destructiveHint: false` when connected to a `writeMode:
"blocked"` source, preserving custom hints.
- Added comprehensive unit tests (`TestGetAnnotations`,
`TestShouldSuppress`).
- Exposed `writeMode: ${BIGQUERY_WRITE_MODE:allowed}` on
`bigquery-source` so prebuilt images can be launched in read-only mode
via environment variables (`BIGQUERY_WRITE_MODE=blocked ./toolbox
--prebuilt bigquery`).
- Added `TestBigQuery_ReadOnlyVulnerabilityBlock` verifying that if a
custom tool is falsely annotated with `readOnlyHint: true` on a
`writeMode: "blocked"` source, BigQuery dry-run validation catches and
rejects mutating SQL statements (like `CREATE TABLE`) before execution.
- Updated the `writeMode` reference table to document coordination with
MCP read-only annotations and tool suppression.
anubhav756 added a commit that referenced this pull request Aug 27, 2026
## Overview
Add support for BigQuery in Toolbox's Read-Only architecture.

When BigQuery is configured with `writeMode: "blocked"`, the source is
recognized as read-only (`IsReadOnly() == true`). `bigquery-execute-sql`
remains available to AI agents for `SELECT` queries as a single
polymorphic tool, dynamically updating its MCP annotations to
`readOnlyHint: true` and `destructiveHint: false`. Any dedicated
mutating tools without read-only annotations are automatically
suppressed.

## Changes

- Updated `BigQuerySource.IsReadOnly()` to return `true` when `WriteMode
== "blocked"`.
- Added unit tests covering all `writeMode` states (`blocked`,
`allowed`, `protected`, empty default).
- Implemented `ShouldSuppress(ctx, source) bool { return false }` so
`execute_sql` remains exposed to agents for `SELECT` queries on
read-only sources.
- Implemented `GetAnnotations(src)` to dynamically return `readOnlyHint:
true` and `destructiveHint: false` when connected to a `writeMode:
"blocked"` source, preserving custom hints.
- Added comprehensive unit tests (`TestGetAnnotations`,
`TestShouldSuppress`).
- Exposed `writeMode: ${BIGQUERY_WRITE_MODE:allowed}` on
`bigquery-source` so prebuilt images can be launched in read-only mode
via environment variables (`BIGQUERY_WRITE_MODE=blocked ./toolbox
--prebuilt bigquery`).
- Added `TestBigQuery_ReadOnlyVulnerabilityBlock` verifying that if a
custom tool is falsely annotated with `readOnlyHint: true` on a
`writeMode: "blocked"` source, BigQuery dry-run validation catches and
rejects mutating SQL statements (like `CREATE TABLE`) before execution.
- Updated the `writeMode` reference table to document coordination with
MCP read-only annotations and tool suppression.
anubhav756 added a commit that referenced this pull request Aug 27, 2026
## Overview
Add support for BigQuery in Toolbox's Read-Only architecture.

When BigQuery is configured with `writeMode: "blocked"`, the source is
recognized as read-only (`IsReadOnly() == true`). `bigquery-execute-sql`
remains available to AI agents for `SELECT` queries as a single
polymorphic tool, dynamically updating its MCP annotations to
`readOnlyHint: true` and `destructiveHint: false`. Any dedicated
mutating tools without read-only annotations are automatically
suppressed.

## Changes

- Updated `BigQuerySource.IsReadOnly()` to return `true` when `WriteMode
== "blocked"`.
- Added unit tests covering all `writeMode` states (`blocked`,
`allowed`, `protected`, empty default).
- Implemented `ShouldSuppress(ctx, source) bool { return false }` so
`execute_sql` remains exposed to agents for `SELECT` queries on
read-only sources.
- Implemented `GetAnnotations(src)` to dynamically return `readOnlyHint:
true` and `destructiveHint: false` when connected to a `writeMode:
"blocked"` source, preserving custom hints.
- Added comprehensive unit tests (`TestGetAnnotations`,
`TestShouldSuppress`).
- Exposed `writeMode: ${BIGQUERY_WRITE_MODE:allowed}` on
`bigquery-source` so prebuilt images can be launched in read-only mode
via environment variables (`BIGQUERY_WRITE_MODE=blocked ./toolbox
--prebuilt bigquery`).
- Added `TestBigQuery_ReadOnlyVulnerabilityBlock` verifying that if a
custom tool is falsely annotated with `readOnlyHint: true` on a
`writeMode: "blocked"` source, BigQuery dry-run validation catches and
rejects mutating SQL statements (like `CREATE TABLE`) before execution.
- Updated the `writeMode` reference table to document coordination with
MCP read-only annotations and tool suppression.
anubhav756 added a commit that referenced this pull request Aug 27, 2026
## Overview
Add support for BigQuery in Toolbox's Read-Only architecture.

When BigQuery is configured with `writeMode: "blocked"`, the source is
recognized as read-only (`IsReadOnly() == true`). `bigquery-execute-sql`
remains available to AI agents for `SELECT` queries as a single
polymorphic tool, dynamically updating its MCP annotations to
`readOnlyHint: true` and `destructiveHint: false`. Any dedicated
mutating tools without read-only annotations are automatically
suppressed.

## Changes

- Updated `BigQuerySource.IsReadOnly()` to return `true` when `WriteMode
== "blocked"`.
- Added unit tests covering all `writeMode` states (`blocked`,
`allowed`, `protected`, empty default).
- Implemented `ShouldSuppress(ctx, source) bool { return false }` so
`execute_sql` remains exposed to agents for `SELECT` queries on
read-only sources.
- Implemented `GetAnnotations(src)` to dynamically return `readOnlyHint:
true` and `destructiveHint: false` when connected to a `writeMode:
"blocked"` source, preserving custom hints.
- Added comprehensive unit tests (`TestGetAnnotations`,
`TestShouldSuppress`).
- Exposed `writeMode: ${BIGQUERY_WRITE_MODE:allowed}` on
`bigquery-source` so prebuilt images can be launched in read-only mode
via environment variables (`BIGQUERY_WRITE_MODE=blocked ./toolbox
--prebuilt bigquery`).
- Added `TestBigQuery_ReadOnlyVulnerabilityBlock` verifying that if a
custom tool is falsely annotated with `readOnlyHint: true` on a
`writeMode: "blocked"` source, BigQuery dry-run validation catches and
rejects mutating SQL statements (like `CREATE TABLE`) before execution.
- Updated the `writeMode` reference table to document coordination with
MCP read-only annotations and tool suppression.
anubhav756 added a commit that referenced this pull request Aug 27, 2026
…ions (#3872)

## Description

This PR introduces end-to-end Read-Only mode support across Toolbox,
spanning core framework tool suppression, source-aware dynamic MCP tool
annotations, and protocol/session-level enforcement for database
sources.

When a data source is configured in read-only mode:
1. **Agent-Level Tool Suppression**: Write-capable tools bound to
read-only sources are suppressed from tool registration and pruned from
tool groups to save LLM context window space and prevent hallucinated
write attempts.
2. **Dynamic Tool Annotations**: Multi-mode tools (such as SQL execution
tools) dynamically advertise `readOnlyHint: true` and `destructiveHint:
false` in MCP tool manifests when connected to read-only sources.
3. **Database Session-Level Enforcement**: Database drivers enforce
strict, protocol-level session locking directly within the database
engine/client driver, preventing prompt injection or multi-statement
write breakouts.

## PRs Included

- #3615
- #3816
- #3618
- #3851
- #3619
- #3617
github-actions Bot pushed a commit that referenced this pull request Aug 27, 2026
…amic tool annotations (#3872)

## Description

This PR introduces end-to-end Read-Only mode support across Toolbox,
spanning core framework tool suppression, source-aware dynamic MCP tool
annotations, and protocol/session-level enforcement for database
sources.

When a data source is configured in read-only mode:
1. **Agent-Level Tool Suppression**: Write-capable tools bound to
read-only sources are suppressed from tool registration and pruned from
tool groups to save LLM context window space and prevent hallucinated
write attempts.
2. **Dynamic Tool Annotations**: Multi-mode tools (such as SQL execution
tools) dynamically advertise `readOnlyHint: true` and `destructiveHint:
false` in MCP tool manifests when connected to read-only sources.
3. **Database Session-Level Enforcement**: Database drivers enforce
strict, protocol-level session locking directly within the database
engine/client driver, preventing prompt injection or multi-statement
write breakouts.

## PRs Included

- #3615
- #3816
- #3618
- #3851
- #3619
- #3617
Yuan325 added a commit that referenced this pull request Aug 27, 2026
🤖 I have created a release *beep* *boop*
---


##
[1.10.0](v1.9.0...v1.10.0)
(2026-08-27)


### Features

* **falkordb:** Add FalkorDB source and tools
([#3692](#3692))
([a94702c](a94702c))
* **firestore-mongodb:** Add firestore-execute-mql and firestore-get-…
([#3826](#3826))
([4a85d75](4a85d75))
* **mcp:** Add Secure Parameters support as Toolbox experimental
extension
([#3394](#3394))
([9750d2d](9750d2d))
* **server/mcp:** Support com.google.cloud/toolbox.v1 extension in
v20260728
([#3801](#3801))
([f4f7da6](f4f7da6))
* **skill:** Add fix-failing-tests skill for mcp-toolbox
([#3821](#3821))
([168e69c](168e69c))
* **sources:** Support native read-only mode and dynamic tool
annotations
([#3872](#3872))
([c257022](c257022)),
refs [#3615](#3615)
[#3816](#3816)
[#3618](#3618)
[#3851](#3851)
[#3619](#3619)
[#3617](#3617)
* **tool/mongodb:** Allow collection to be specified at runtime
([#3715](#3715))
([7626eaf](7626eaf))


### Bug Fixes

* **cloud-storage:** Resolve symlinks when enforcing local path
boundaries
([#3810](#3810))
([c2ada64](c2ada64))
* **config:** Compare env var offsets in rune space when skipping
comments
([#3856](#3856))
([2e76934](2e76934))
* Merge prebuilt tools when reloading custom config
([#3864](#3864))
([5a6d865](5a6d865))
* Normalize postgres UUIDs to strings
([#3806](#3806))
([3b02f1d](3b02f1d))
* **postgres:** Filter background processes in
postgres-list-active-queries
([#3885](#3885))
([3d9e62a](3d9e62a))
* **test/alloydbainl:** Use explicit SQL alias prompts to stabilize AI…
([#3877](#3877))
([50e45ed](50e45ed))
* **tests:** Prevent resource leaks by using context.WithoutCancel
([#3849](#3849))
([f97a4f9](f97a4f9))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

---------

Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com>
Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com>
github-actions Bot pushed a commit that referenced this pull request Aug 27, 2026
🤖 I have created a release *beep* *boop*
---

##
[1.10.0](v1.9.0...v1.10.0)
(2026-08-27)

### Features

* **falkordb:** Add FalkorDB source and tools
([#3692](#3692))
([a94702c](a94702c))
* **firestore-mongodb:** Add firestore-execute-mql and firestore-get-…
([#3826](#3826))
([4a85d75](4a85d75))
* **mcp:** Add Secure Parameters support as Toolbox experimental
extension
([#3394](#3394))
([9750d2d](9750d2d))
* **server/mcp:** Support com.google.cloud/toolbox.v1 extension in
v20260728
([#3801](#3801))
([f4f7da6](f4f7da6))
* **skill:** Add fix-failing-tests skill for mcp-toolbox
([#3821](#3821))
([168e69c](168e69c))
* **sources:** Support native read-only mode and dynamic tool
annotations
([#3872](#3872))
([c257022](c257022)),
refs [#3615](#3615)
[#3816](#3816)
[#3618](#3618)
[#3851](#3851)
[#3619](#3619)
[#3617](#3617)
* **tool/mongodb:** Allow collection to be specified at runtime
([#3715](#3715))
([7626eaf](7626eaf))

### Bug Fixes

* **cloud-storage:** Resolve symlinks when enforcing local path
boundaries
([#3810](#3810))
([c2ada64](c2ada64))
* **config:** Compare env var offsets in rune space when skipping
comments
([#3856](#3856))
([2e76934](2e76934))
* Merge prebuilt tools when reloading custom config
([#3864](#3864))
([5a6d865](5a6d865))
* Normalize postgres UUIDs to strings
([#3806](#3806))
([3b02f1d](3b02f1d))
* **postgres:** Filter background processes in
postgres-list-active-queries
([#3885](#3885))
([3d9e62a](3d9e62a))
* **test/alloydbainl:** Use explicit SQL alias prompts to stabilize AI…
([#3877](#3877))
([50e45ed](50e45ed))
* **tests:** Prevent resource leaks by using context.WithoutCancel
([#3849](#3849))
([f97a4f9](f97a4f9))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

---------

Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com>
Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com>
social4hyq pushed a commit to social4hyq/homebrew-core that referenced this pull request Sep 20, 2026
mcp-toolbox 1.10.0

Created-by: HarmonybrewBot
Commit-by: HarmonybrewBot
Merged-by: HarmonybrewBot
Description: Created by `brew bump`

---

Created with `brew bump-formula-pr`.
release notes
## [1.10.0](googleapis/mcp-toolbox@v1.9.0...v1.10.0) (2026-08-27)


### Features

* **falkordb:** Add FalkorDB source and tools ([#3692](googleapis/mcp-toolbox#3692)) ([a94702c](googleapis/mcp-toolbox@a94702c))
* **mcp:** Add Secure Parameters support as Toolbox experimental extension ([#3394](googleapis/mcp-toolbox#3394)) ([9750d2d](googleapis/mcp-toolbox@9750d2d))
* **server/mcp:** Support com.google.cloud/toolbox.v1 extension in v20260728 ([#3801](googleapis/mcp-toolbox#3801)) ([f4f7da6](googleapis/mcp-toolbox@f4f7da6))
* **skill:** Add fix-failing-tests skill for mcp-toolbox ([#3821](googleapis/mcp-toolbox#3821)) ([168e69c](googleapis/mcp-toolbox@168e69c))
* **sources:** Support native read-only mode and dynamic tool annotations ([#3872](googleapis/mcp-toolbox#3872)) ([c257022](googleapis/mcp-toolbox@c257022)), refs [#3615](googleapis/mcp-toolbox#3615) [#3816](googleapis/mcp-toolbox#3816) [#3618](googleapis/mcp-toolbox#3618) [#3851](googleapis/mcp-toolbox#3851) [#3619](googleapis/mcp-toolbox#3619) [#3617](googleapis/mcp-toolbox#3617)
* **tools/firestore-mongodb:** Add tools for execute mql and get schema ([#3826](googleapis/mcp-toolbox#3826)) ([4a85d75](googleapis/mcp-toolbox@4a85d75))
* **tool/mongodb:** Allow collection to be specified at runtime ([#3715](googleapis/mcp-toolbox#3715)) ([7626eaf](googleapis/mcp-toolbox@7626eaf))


### Bug Fixes

* **cloud-storage:** Resolve symlinks when enforcing local path boundaries ([#3810](googleapis/mcp-toolbox#3810)) ([c2ada64](googleapis/mcp-toolbox@c2ada64))
* **config:** Compare env var offsets in rune space when skipping comments ([#3856](googleapis/mcp-toolbox#3856)) ([2e76934](googleapis/mcp-toolbox@2e76934))
* Merge prebuilt tools when reloading custom config ([#3864](googleapis/mcp-toolbox#3864)) ([5a6d865](googleapis/mcp-toolbox@5a6d865))
* Normalize postgres UUIDs to strings ([#3806](googleapis/mcp-toolbox#3806)) ([3b02f1d](googleapis/mcp-toolbox@3b02f1d))
* **postgres:** Filter background processes in postgres-list-active-queries ([#3885](googleapis/mcp-toolbox#3885)) ([3d9e62a](googleapis/mcp-toolbox@3d9e62a))

| **OS/Architecture**                                                                                       | **Description**                                                                                                          | **SHA256 Hash**                                                     |
| --------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------- |
| [linux/amd64](https://storage.googleapis.com/mcp-toolbox-for-databases/v1.10.0/linux/amd64/toolbox) ([Signature](https://storage.googleapis.com/mcp-toolbox-for-databases/v1.10.0/linux/amd64/toolbox.asc)) | For **Linux** systems running on **Intel/AMD 64-bit processors**.                                                        | 7e15dba09e6f957f64ce5924a0aa06b12cdf83ab26119813b0fa40edab566dd4    |
| [darwin/arm64](https://storage.googleapis.com/mcp-toolbox-for-databases/v1.10.0/darwin/arm64/toolbox)     | For **macOS** systems running on **Apple Silicon** (M1, M2, M3, etc.) processors.                                        | c994f06781462abba4171cb4844776c45605e391c57dc96adb3e130c81b53825    |
| [darwin/amd64](https://storage.googleapis.com/mcp-toolbox-for-databases/v1.10.0/darwin/amd64/toolbox)     | For **macOS** systems running on **Intel processors**.                                                                   | 12ebf78d9d05e8f3fe90c5d02ae14f2ccd96cf036f3dfba430bc32e3cfeadfd4    |
| [windows/amd64](https://storage.googleapis.com/mcp-toolbox-for-databases/v1.10.0/windows/amd64/toolbox.exe) | For **Windows** systems running on **Intel/AMD 64-bit processors**.                                                      | 734783941cb5864c0e5d4d78be625f8b12be23b01d94781d7fa7db9b3c25aac6    |
| [windows/arm64](https://storage.googleapis.com/mcp-toolbox-for-databases/v1.10.0/windows/arm64/toolbox.exe) | For **Windows** systems running on **ARM 64-bit processors**.                                                            | d9be7c2ce1d2e29c20f2974cbac4cde857adad836cee565d2584f3fbcc97f096    |

View the full release notes at https://github.com/googleapis/mcp-toolbox/releases/tag/v1.10.0">https://github.com/googleapis/mcp-toolbox/releases/tag/v1.10.0.>


See merge request: Harmonybrew/homebrew-core!17982
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority: p1 Important issue which blocks shipping the next release. Will be fixed prior to next release.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants