Skip to content

Intercept an MCP tool result

Goal: alter a tool result before the MCP client consumes it.

Start with the process-backed exercise:

ait lab start --exercise mcp-tool-result

Trigger the traffic in the Lab drawer, select the MCP response, change /result/structuredContent/risk, and forward modified. The client decision and effect ledger show exactly which value was consumed.

For Streamable HTTP, save the MCP server as mcp_http, place the AIT listener in the client's server configuration, and break on response traffic for the tool call. For stdio, configure the MCP client to launch the packaged AIT/Seam wrapper instead of launching the server directly.

  1. Start the explicit relay or wrapper.
  2. Invoke the tool from the MCP client.
  3. Select the correlated response.
  4. Edit only the intended result field in Structured mode.
  5. Forward modified and inspect what the client received.
  6. Compare with Original on the next call or disable interception.

Keep authorization headers and credentials referenced rather than copied into reusable edits. Raw captures retain credential values; redacted export replaces them. A saved live rule should describe a bounded field change without storing an unrelated secret.

For stdio, ait intercept start prints the exact replacement command. Use it unchanged in the MCP client configuration so the wrapper registers with the same Cockpit session.