Appearance
SEC573 / MCP-AUTOAPPROVE-WEBSEARCH-WILDCARD
SEC573 flags MCP configuration when autoApprove includes the exact tool token WebSearch(*).
Why It Matters
WebSearch(*) grants blanket remote search authority. Auto-approving it removes review from broad outbound search in shared MCP client policy.
Trigger Shape
- the file is a detected MCP configuration surface
autoApproveis a string array- the array contains the exact item
WebSearch(*)
How To Fix
Remove WebSearch(*) from autoApprove and replace it with narrower reviewed search scopes where possible.