Current behavior
MCPTool._load_prompts_locked refreshes prompts append-only: it records existing function names, skips prompt names already loaded, and extends _functions only with unseen names.
Consequences:
- Prompts removed by the server remain exposed.
- A successful empty prompt snapshot does not clear previously loaded prompt functions.
- Changed prompt descriptions or arguments remain stale.
Expected behavior
Treat a successful, complete prompts/list fetch as the current prompt catalog, while preserving unrelated MCP tools and user-added functions. Build the refreshed prompt catalog without publishing partial results; if pagination fails, retain the previous catalog rather than applying an incomplete snapshot.
Scope
This is protocol-version independent and affects both legacy list-change notifications and modern subscriptions. It was discovered during the MCP v2 work, but is not caused by v2.
Related to #8245. This issue should not expand or block the base v2 migration unless maintainers choose otherwise.
Relevant source: python/packages/core/agent_framework/_mcp.py, method _load_prompts_locked.
Current behavior
MCPTool._load_prompts_lockedrefreshes prompts append-only: it records existing function names, skips prompt names already loaded, and extends_functionsonly with unseen names.Consequences:
Expected behavior
Treat a successful, complete
prompts/listfetch as the current prompt catalog, while preserving unrelated MCP tools and user-added functions. Build the refreshed prompt catalog without publishing partial results; if pagination fails, retain the previous catalog rather than applying an incomplete snapshot.Scope
This is protocol-version independent and affects both legacy list-change notifications and modern subscriptions. It was discovered during the MCP v2 work, but is not caused by v2.
Related to #8245. This issue should not expand or block the base v2 migration unless maintainers choose otherwise.
Relevant source:
python/packages/core/agent_framework/_mcp.py, method_load_prompts_locked.