MCP-CAC-005
Authenticated or personalised results are not marked cacheScope: public
“A `cacheScope` of `"public"` indicates that the response does not contain user-specific data and can be safely shared.” — spec anchor
How to fix this
Not a spec MUST — a data-leak class where a shared intermediary caches a per-user result. Stays a warn forever; explain clearly rather than escalating.
How the validator checks this
Probe P2.1, against a streamable-http server on the modern protocol. What it reports:
- info
- … declare cacheScope "public". We probe unauthenticated and cannot tell whether these vary per user — if any does, "public" lets a shared cache serve one caller's list to another.
Quoted from the probe that runs this check, so it cannot drift from what the validator actually reports.
This rule is checked heuristically: a fail is inferred rather than certain, so it bumps the overall grade up one level instead of being treated as certain non-compliance.
Checked in the same request as MCP-HDR-008, MCP-HDR-009, MCP-RES-003, MCP-RES-006, MCP-RES-007, MCP-ERR-003, MCP-ERR-004, MCP-ERR-005, MCP-ERR-008, MCP-CAC-001, MCP-CAC-002, MCP-CAC-003, MCP-CAC-004, MCP-SCH-001, MCP-SCH-002, MCP-SCH-003, MCP-SCH-004, MCP-SCH-005, MCP-SCH-006, MCP-SCH-007, MCP-SEC-004, MCP-SEC-005, MCP-SEC-006, MCP-DEP-005.
Check your own server against this rule
The validator makes real protocol requests and reports this rule as pass, warn or fail alongside the other 78. Validate a server or read how the check works.
Other Caching metadata rules
- MCP-CAC-001ttlMs present on all five cacheable results
- MCP-CAC-002cacheScope present on all five cacheable results
- MCP-CAC-003cacheScope is exactly "public" or "private"
- MCP-CAC-004ttlMs is a non-negative number