createmcps.com

MCP-CAC-003

cacheScope is exactly "public" or "private"

cacheScope ("public" or "private").spec anchor

How to fix this

Set `cacheScope` to exactly `"public"` or `"private"` — no other value is defined. It controls whether shared intermediaries may cache the response, so a wrong value is a disclosure risk rather than a cosmetic one.

How the validator checks this

Probe P2.1, against a streamable-http server on the modern protocol. What it reports:

pass
Every cacheScope is exactly "public" or "private"
fail
cacheScope must be "public" or "private" — got

Quoted from the probe that runs this check, so it cannot drift from what the validator actually reports.

This rule is checked deterministically: a fail here is a certain violation, not an inference.

Checked in the same request as MCP-HDR-008, MCP-HDR-009, MCP-RES-003, MCP-RES-006, MCP-RES-007, MCP-ERR-003, MCP-ERR-004, MCP-ERR-005, MCP-ERR-008, MCP-CAC-001, MCP-CAC-002, MCP-CAC-004, MCP-CAC-005, MCP-SCH-001, MCP-SCH-002, MCP-SCH-003, MCP-SCH-004, MCP-SCH-005, MCP-SCH-006, MCP-SCH-007, MCP-SEC-004, MCP-SEC-005, MCP-SEC-006, MCP-DEP-005.

Check your own server against this rule

The validator makes real protocol requests and reports this rule as pass, warn or fail alongside the other 78. Validate a server or read how the check works.

Other Caching metadata rules

  • MCP-CAC-001ttlMs present on all five cacheable results
  • MCP-CAC-002cacheScope present on all five cacheable results
  • MCP-CAC-004ttlMs is a non-negative number
  • MCP-CAC-005Authenticated or personalised results are not marked cacheScope: public