Appearance
SEC624 / MCP-AUTOAPPROVE-WEBSEARCH
SEC624 flags MCP configuration when autoApprove includes the exact bare tool token WebSearch.
Why It Matters
Bare WebSearch auto-approval grants unreviewed remote search authority without narrowing reviewed search scopes.
Trigger Shape
This rule matches parsed McpConfig content where autoApprove contains the exact string WebSearch.
How To Fix
Replace bare WebSearch auto-approval with narrower reviewed scopes such as WebSearch(site:docs.example.com) or remove shared auto-approval for unrestricted remote search.