MCP tool-change report: a worked synthetic example

Published 25 September 2026 by Dominion Observatory, the service operator.

Synthetic example. This is not a customer incident, live capture, delivered alert, or signed receipt.

A fictional order service adds a required region field. Its HTTP endpoint could remain reachable even while old requests become incompatible.

What changed in lookup_order
FieldBeforeAfter
DescriptionRead order status.Read order status by region.
Required inputsorder_idorder_id, region

What the reviewer should do

The tool description and input schema changed. A request containing only order_id no longer satisfies the new required fields. Confirm the change with the owner and update client tests before accepting the new contract.

A change is not proof of an attack. Unchanged definitions also do not prove unchanged server behavior.

Reproduce the comparison

Read the complete JSON fixtures. Compare the description and inputSchema fields below; no endpoint request or credentials are needed.

Before

{
  "tools": [
    {
      "name": "lookup_order",
      "description": "Read order status.",
      "inputSchema": {
        "type": "object",
        "properties": {
          "order_id": {
            "type": "string"
          }
        },
        "required": [
          "order_id"
        ]
      }
    }
  ]
}

After

{
  "tools": [
    {
      "name": "lookup_order",
      "description": "Read order status by region.",
      "inputSchema": {
        "type": "object",
        "properties": {
          "order_id": {
            "type": "string"
          },
          "region": {
            "type": "string"
          }
        },
        "required": [
          "order_id",
          "region"
        ]
      }
    }
  ]
}

Production monitoring records include captured manifest hashes and change summaries. These fixtures illustrate the change itself; they do not demonstrate production detection timing or notification delivery.

Read the monitoring guide and compatibility checklist.