createmcps.com

MCP-CAC-005

Authenticated or personalised results are not marked cacheScope: public

A `cacheScope` of `"public"` indicates that the response does not contain user-specific data and can be safely shared.spec anchor

How to fix this

Not a spec MUST — a data-leak class where a shared intermediary caches a per-user result. Stays a warn forever; explain clearly rather than escalating.

How the validator checks this

Probe P2.1, against a streamable-http server on the modern protocol. What it reports:

info
… declare cacheScope "public". We probe unauthenticated and cannot tell whether these vary per user — if any does, "public" lets a shared cache serve one caller's list to another.

Quoted from the probe that runs this check, so it cannot drift from what the validator actually reports.

This rule is checked heuristically: a fail is inferred rather than certain, so it bumps the overall grade up one level instead of being treated as certain non-compliance.

Checked in the same request as MCP-HDR-008, MCP-HDR-009, MCP-RES-003, MCP-RES-006, MCP-RES-007, MCP-ERR-003, MCP-ERR-004, MCP-ERR-005, MCP-ERR-008, MCP-CAC-001, MCP-CAC-002, MCP-CAC-003, MCP-CAC-004, MCP-SCH-001, MCP-SCH-002, MCP-SCH-003, MCP-SCH-004, MCP-SCH-005, MCP-SCH-006, MCP-SCH-007, MCP-SEC-004, MCP-SEC-005, MCP-SEC-006, MCP-DEP-005.

Check your own server against this rule

The validator makes real protocol requests and reports this rule as pass, warn or fail alongside the other 78. Validate a server or read how the check works.

Other Caching metadata rules