AEM as a Cloud Service: Prevent write operations on Content (read-only) MCP Server

This article explains how to enforce read-only restrictions on the Adobe Experience Manager as a Cloud Service (AEMaaCS) Content (read-only) MCP Server. Certain MCP tools may expose content creation, modification, or deletion capabilities even when the server is intended to operate in read-only mode. To resolve the issue, remove write-enabled tools from the allowlist.

Description description

Environment

Adobe Experience Manager as a Cloud Service (AEMaaCS) (all versions)

Issue/Symptoms

  • The Content (read-only) MCP Server exposes write operations through the following tools:

    • manage-aem-fragment-variations supports create, patch, delete, list, and get operations.
    • manage-aem-fragment-versions supports create, restore, list, and get operations.
  • This behavior allows content creation, modification, or deletion through the MCP Server even though the server is intended to enforce read-only restrictions. As a result, developers or other users may make unintended content changes.

Steps to reproduce:

  1. Install an MCP Server by following the documented setup process.
  2. Attempt write operations such as creating content variations or restoring versions through the MCP Server.
  3. Verify that the operations succeed even though the server is configured as read-only.

Root cause

The Content (read-only) MCP Server exposes write operations because write-enabled tools are included in the MCP Server allowlist. Removing these tools enforces the intended read-only behavior.

Resolution resolution

Follow the steps below to resolve the issue:

  1. Confirm that the MCP Server is intended to operate in read-only mode.

  2. Update the MCP Server configuration and remove the following tools from the allowlist:

    • manage-aem-fragment-variations
    • manage-aem-fragment-versions
  3. Make the changes at the server or tool-allowlist layer as described in the MCP Server documentation.

  4. Apply the updated configuration to the Adobe Experience Manager (AEMaaCS) as a Cloud Service environment.

  5. Ensure that the MCP Server restarts or reloads the updated configuration.

  6. Attempt write operations such as create, patch, delete, or restore actions through the MCP Server.

  7. Verify the resolution by confirming that write operations are no longer available or permitted on the Content (read-only) MCP Server.

recommendation-more-help
experience-cloud-kcs-help-kbarticles