Problem or motivation
call-actor is destructiveHint: true because it can run any Actor. Annotations are fixed per tool in tools/list, so the hint can't depend on which Actor is called. Claude always prompts for destructive tools (review criteria), so every call-actor call asks for approval. Most Actors only read: 85% of the 658 Actors labelled in the survey in #1446.
The same checklist rejects one tool that accepts both safe and unsafe HTTP methods, and asks for read and write to be separate tools. call-actor has the same shape. Context: the Slack thread, where jancurn proposed call-actor + call-actor-unsafe.
Proposed solution
call-actor: readOnlyHint: true. It runs only Actors classified read-only. Any other Actor fails with an error naming the second tool.
- A second tool (name TBD, e.g.
call-actor-unsafe): destructiveHint: true. It runs any Actor.
- The tool descriptions, and possibly
fetch-actor-details, tell the LLM which tool fits which Actor.
Classification:
Precedent: Zapier MCP ships execute_zapier_read_action and execute_zapier_write_action (docs).
Open questions
Alternatives considered
- A parameter on
call-actor that allows destructive Actors. Doesn't help: the hint is read from tools/list before the call, so the client still has to treat the tool as destructive.
- Keep
call-actor destructive. Every Actor run through call-actor keeps prompting.
Analysis prepared with Claude Code.
Problem or motivation
call-actorisdestructiveHint: truebecause it can run any Actor. Annotations are fixed per tool intools/list, so the hint can't depend on which Actor is called. Claude always prompts for destructive tools (review criteria), so everycall-actorcall asks for approval. Most Actors only read: 85% of the 658 Actors labelled in the survey in #1446.The same checklist rejects one tool that accepts both safe and unsafe HTTP methods, and asks for read and write to be separate tools.
call-actorhas the same shape. Context: the Slack thread, where jancurn proposedcall-actor+call-actor-unsafe.Proposed solution
call-actor:readOnlyHint: true. It runs only Actors classified read-only. Any other Actor fails with an error naming the second tool.call-actor-unsafe):destructiveHint: true. It runs any Actor.fetch-actor-details, tell the LLM which tool fits which Actor.Classification:
isReadOnlyActorfrom the [Feature]: Flag directly added public Actors with limited permissions with non-destructive hint #973 fix works now.Precedent: Zapier MCP ships
execute_zapier_read_actionandexecute_zapier_write_action(docs).Open questions
call-actor-widget) gets the same split.call-task: a task runs an Actor, so it inherits the same split.Alternatives considered
call-actorthat allows destructive Actors. Doesn't help: the hint is read fromtools/listbefore the call, so the client still has to treat the tool as destructive.call-actordestructive. Every Actor run throughcall-actorkeeps prompting.Analysis prepared with Claude Code.