What you want to read or modify
Account, service, and file permissions
Execution results are constrained by the environment
Permission: The scope of accessible resources and executable operations controlled by applications, services, and runtime environments.
First, Clarify What You Allow It to Do
Preparing materials requires reading specified resources; modifying original files and sending them to others are separate operations. It is unreasonable to interpret "helping with lesson preparation" as meaning access to all files or sending content externally.
Permissions are enforced by applications, services, and runtime environments. Prompts can express operational requirements, but they are not actual access controls themselves.
Three Operations, Evaluated Separately
| Operation | Scope Requiring Confirmation |
|---|---|
| Read | Which files, directories, or service records can be accessed |
| Modify | Which content can be changed, and how to verify and restore |
| Send or Publish | Where to, to whom, and whether the final content is determined |
Specific environments may bundle multiple capabilities together or grant them separately. Examine the actual operational scope, not just "connected" or "installed" status.
"Do Not Delete" Is Not a Read-Only Setting
Requiring "do not delete" in a prompt is guidance for system behavior. If the tool still has deletion capabilities, the actual permissions have not changed as a result.
Conversely, even if you request "please modify the file," the tool cannot complete a write operation if it only has a read interface. Task requirements and executable scope need to be consistent.
Understanding Boundaries with MCP Examples
The course materials service on this site only exposes reading of fixed materials by course ID, does not accept arbitrary file paths, and has no modification or sending tools. This defines the operations the service provides, but does not mean the entire Python process is read-only at the operating system level.
When switching to a different service, re-verify its capabilities and actual permissions. Do not assume the same access scope just because they all use MCP.
Practical Judgment When Using
Choose resources and operation scope according to task requirements. Confirm the target before operating and check results afterward; if the scope does not match the task, first adjust connections, tools, or settings. Specific authorization interfaces vary by application.
Next Steps
Read Tools and MCP to understand how requirements, capabilities, and access conditions work together.
Reflect
Does writing "do not modify files" in a prompt equal the tool being set to read-only?
Reference judgment: No. Actual read-only requires tool and environment restrictions on write operations; a prompt request is merely behavioral guidance.
Sources and Scope of Application
References OpenAI · Using tools, MCP · Tools. Technical specifications verified on 2026-09-09; cases and instructional organization are authored by this site. Specific product support scope and operational methods should be verified separately; this article makes no cross-product feature commitments.