From 88369af1c7219b49257a994a0b933f48c8fa3ef8 Mon Sep 17 00:00:00 2001 From: Teknium <127238744+teknium1@users.noreply.github.com> Date: Tue, 25 Aug 2026 00:56:56 -0700 Subject: [PATCH] =?UTF-8?q?refine(mcp):=20debloat=20the=20catalog=20batch?= =?UTF-8?q?=20=E2=80=94=20vendor-doc=20tool=20audit=20applied=20to=20every?= =?UTF-8?q?=20entry?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Policy applied (per Teknium direction, matching the Cloudflare precedent): raw tool surfaces only — no server-side code-mode/search-execute layers, no vendor tool_search; bloat (telemetry, feedback, docs-lookup, static-guidance pseudo-tools, plan-gated upsells, dupe batch/compat shims) pruned via manifest defaults. DROPPED (meta-tool gateway IS the server, no vendor off-switch): zapier (discover/enable/execute over 40k actions), wix (CallWixSiteAPI generic invoke), customer-io (cio_read/write/delete_api generic HTTP executors), omnisend (4 generic verb executors), apify (dynamic actor-mount + telemetry-on-by-default), ramp (undocumented SQL/ETL layer, no tool list, money-moving approval tools) URL-LEVEL DEBLOAT (vendor-documented switches): postman -> /minimal variant; klaviyo -> ?core-tools-only=true& disable-tools-with-user-generated-content=true (262 -> ~40 tools) CURATED default_excluded (20 entries) / default_enabled (kiwi, motherduck): monday (GraphQL escape hatch trio...), close (voice-agent cluster that places real AI phone calls, search/fetch layer, 14 excl), betterstack (Execute query SQL hatch, 8 instruction pseudo-tools, team mgmt, 14 excl), mixpanel (6 guidance pseudo-tools, bulk dupes, 10 excl), neon (search/ fetch, docs pair, logs beta, auth product, 10 excl), miro (6 deprecated), gamma (viewer-tracking analytics), robinhood (upsell+social), dropbox, todoist, fireflies, calendly, plaid, attio, gitlab, circleci, buildkite (secrets-exposing get_job_env), semgrep, globalping, prisma-postgres, motherduck (9-tool core enable), kiwi (feedback tool pruned) Clean after audit (no changes needed): canva, clickup, linear-class lean servers, twelve-data (read-only), algolia (read-only, vendor-curated), indeed, strava (vendor read-only, no tool list published), craft, wordpress-com (user-side toggles documented), trivago, alltrails, deepwiki, context7, microsoft-learn, aws-knowledge, wolfram, twilio-docs --- optional-mcps/alltrails/manifest.yaml | 5 +++ optional-mcps/apify/manifest.yaml | 33 ------------------- optional-mcps/attio/manifest.yaml | 7 ++++ optional-mcps/betterstack/manifest.yaml | 23 +++++++++++++ optional-mcps/buildkite/manifest.yaml | 7 ++++ optional-mcps/calendly/manifest.yaml | 7 ++++ optional-mcps/circleci/manifest.yaml | 6 ++++ optional-mcps/close/manifest.yaml | 22 +++++++++++++ optional-mcps/customer-io/manifest.yaml | 35 -------------------- optional-mcps/dropbox/manifest.yaml | 8 +++++ optional-mcps/fireflies/manifest.yaml | 7 ++++ optional-mcps/gamma/manifest.yaml | 8 +++++ optional-mcps/gitlab/manifest.yaml | 6 ++++ optional-mcps/globalping/manifest.yaml | 7 ++++ optional-mcps/kiwi/manifest.yaml | 7 ++++ optional-mcps/klaviyo/manifest.yaml | 6 +++- optional-mcps/miro/manifest.yaml | 11 +++++++ optional-mcps/mixpanel/manifest.yaml | 16 +++++++++ optional-mcps/monday/manifest.yaml | 12 +++++++ optional-mcps/motherduck/manifest.yaml | 15 +++++++++ optional-mcps/neon/manifest.yaml | 16 +++++++++ optional-mcps/omnisend/manifest.yaml | 32 ------------------ optional-mcps/plaid/manifest.yaml | 5 +++ optional-mcps/postman/manifest.yaml | 5 ++- optional-mcps/prisma-postgres/manifest.yaml | 5 +++ optional-mcps/ramp/manifest.yaml | 36 --------------------- optional-mcps/robinhood/manifest.yaml | 10 ++++++ optional-mcps/semgrep/manifest.yaml | 9 ++++++ optional-mcps/todoist/manifest.yaml | 9 ++++++ optional-mcps/wix/manifest.yaml | 32 ------------------ optional-mcps/zapier/manifest.yaml | 36 --------------------- 31 files changed, 237 insertions(+), 206 deletions(-) delete mode 100644 optional-mcps/apify/manifest.yaml delete mode 100644 optional-mcps/customer-io/manifest.yaml delete mode 100644 optional-mcps/omnisend/manifest.yaml delete mode 100644 optional-mcps/ramp/manifest.yaml delete mode 100644 optional-mcps/wix/manifest.yaml delete mode 100644 optional-mcps/zapier/manifest.yaml diff --git a/optional-mcps/alltrails/manifest.yaml b/optional-mcps/alltrails/manifest.yaml index 19af1b8783..0e3f1f8bd9 100644 --- a/optional-mcps/alltrails/manifest.yaml +++ b/optional-mcps/alltrails/manifest.yaml @@ -29,3 +29,8 @@ suggest: post_install: | No account or credentials needed — tools are available as soon as the session restarts. + + Heads-up: only 5 tools, but their schemas are unusually verbose (~24K + tokens total). If you only browse trails occasionally, consider leaving + this server disabled and enabling it on demand, or prune tools with: + hermes mcp configure alltrails diff --git a/optional-mcps/apify/manifest.yaml b/optional-mcps/apify/manifest.yaml deleted file mode 100644 index a000abc9b3..0000000000 --- a/optional-mcps/apify/manifest.yaml +++ /dev/null @@ -1,33 +0,0 @@ -# Nous-approved MCP catalog entry. -# Presence in this directory = approval. Merged via PR review. -manifest_version: 1 - -name: apify -description: Run 6,000+ Apify Actors for scraping and automation. -source: https://docs.apify.com/platform/integrations/mcp - -# Official vendor-hosted remote MCP (URL-only — Hermes never spawns a local -# process for this entry). Native OAuth 2.1 + Dynamic Client Registration -# (verified live: RFC 9728 protected-resource metadata -> AS metadata with -# registration_endpoint); Hermes's MCP client + mcp_oauth_manager handle -# discovery, PKCE, token exchange, and refresh. - -transport: - type: http - url: https://mcp.apify.com - -auth: - type: oauth - -# Composer-suggestion triggers (desktop brand pills). -suggest: - keywords: - - apify - - scraper - hosts: - - apify.com - -post_install: | - On first connection Hermes opens a browser to authorize with - Apify (or run `hermes mcp login apify`). Approve access, - then restart the session so tools load. diff --git a/optional-mcps/attio/manifest.yaml b/optional-mcps/attio/manifest.yaml index 5a9e66ba45..80f50ac360 100644 --- a/optional-mcps/attio/manifest.yaml +++ b/optional-mcps/attio/manifest.yaml @@ -19,6 +19,13 @@ transport: auth: type: oauth +# Excluded: trivial identity probe; query-particle-sql is a plan-gated +# generic SQL escape hatch. +tools: + default_excluded: + - whoami + - query-particle-sql + # Composer-suggestion triggers (desktop brand pills). suggest: keywords: diff --git a/optional-mcps/betterstack/manifest.yaml b/optional-mcps/betterstack/manifest.yaml index 6306c61f59..69af2ded47 100644 --- a/optional-mcps/betterstack/manifest.yaml +++ b/optional-mcps/betterstack/manifest.yaml @@ -18,6 +18,29 @@ transport: auth: type: oauth +# Curated exclude list (106-tool surface). Excluded: vendor-docs search; +# eight instruction-fetcher pseudo-tools (static how-to text as tools); +# Execute query / Create cloud connection (raw ClickHouse-SQL escape hatch + +# direct-DB credential minting); team-membership management (account access +# changes). ~85 product tools stay enabled; re-enable any with +# `hermes mcp configure betterstack`. +tools: + default_excluded: + - Search documentation + - Get query instructions + - Get metric query instructions + - Get errors query instructions + - Get replays query instructions + - Get explore logs query instructions + - Get chart building instructions + - Get chart alert instructions + - Get dashboard query instructions + - Execute query + - Create cloud connection + - Invite team member + - Remove team member + - Change team member role + # Composer-suggestion triggers (desktop brand pills). suggest: keywords: diff --git a/optional-mcps/buildkite/manifest.yaml b/optional-mcps/buildkite/manifest.yaml index 8566e80ec9..4274ccdbf5 100644 --- a/optional-mcps/buildkite/manifest.yaml +++ b/optional-mcps/buildkite/manifest.yaml @@ -19,6 +19,13 @@ transport: auth: type: oauth +# Excluded: access_token (token self-probe) and get_job_env (can expose +# secrets from CI env vars into model context). +tools: + default_excluded: + - access_token + - get_job_env + # Composer-suggestion triggers (desktop brand pills). suggest: keywords: diff --git a/optional-mcps/calendly/manifest.yaml b/optional-mcps/calendly/manifest.yaml index 8709020fa6..a5ca67c7d3 100644 --- a/optional-mcps/calendly/manifest.yaml +++ b/optional-mcps/calendly/manifest.yaml @@ -19,6 +19,13 @@ transport: auth: type: oauth +# Excluded: vendor skill-discovery pair (instruction-loading indirection — +# Hermes skills/tool_search cover this). +tools: + default_excluded: + - list_calendly_skills + - load_calendly_skill + # Composer-suggestion triggers (desktop brand pills). suggest: keywords: diff --git a/optional-mcps/circleci/manifest.yaml b/optional-mcps/circleci/manifest.yaml index 5a8f7ba2fb..2dd4eae6e9 100644 --- a/optional-mcps/circleci/manifest.yaml +++ b/optional-mcps/circleci/manifest.yaml @@ -19,6 +19,12 @@ transport: auth: type: oauth +# Excluded: connectivity ping and billing-CSV power-user probe. +tools: + default_excluded: + - hello + - download_usage_data + # Composer-suggestion triggers (desktop brand pills). suggest: keywords: diff --git a/optional-mcps/close/manifest.yaml b/optional-mcps/close/manifest.yaml index 11358d2266..cd1c719627 100644 --- a/optional-mcps/close/manifest.yaml +++ b/optional-mcps/close/manifest.yaml @@ -19,6 +19,28 @@ transport: auth: type: oauth +# Excluded (107-tool surface): product-help search; generic search/fetch/ +# paginate layer duplicating lead_search/activity_search; AI field +# enrichment; and the entire voice-agent cluster — schedule_voice_agent_call +# places REAL outbound AI phone calls to contacts. Re-enable any with +# `hermes mcp configure close`. +tools: + default_excluded: + - close_product_knowledge_search + - customized_builtin_labels + - search + - fetch + - paginate_search + - enrich_field + - schedule_voice_agent_call + - apply_voice_agent_update + - propose_voice_agent_update + - find_voice_agents + - find_agent_configs + - get_voice_agents + - get_voice_agent_overview_report + - get_voice_agent_performance_report + # Composer-suggestion triggers (desktop brand pills). suggest: keywords: diff --git a/optional-mcps/customer-io/manifest.yaml b/optional-mcps/customer-io/manifest.yaml deleted file mode 100644 index 333be8f3b3..0000000000 --- a/optional-mcps/customer-io/manifest.yaml +++ /dev/null @@ -1,35 +0,0 @@ -# Nous-approved MCP catalog entry. -# Presence in this directory = approval. Merged via PR review. -manifest_version: 1 - -name: customer-io -description: 'Customer.io: segments, automations, sends, and CDP data.' -source: https://docs.customer.io/ai/mcp/get-started/ - -# Official vendor-hosted remote MCP (URL-only — Hermes never spawns a local -# process for this entry). Native OAuth 2.1 + Dynamic Client Registration -# (verified live: RFC 9728 protected-resource metadata -> AS metadata with -# registration_endpoint); Hermes's MCP client + mcp_oauth_manager handle -# discovery, PKCE, token exchange, and refresh. - -transport: - type: http - url: https://mcp.customer.io/mcp - -auth: - type: oauth - -# Composer-suggestion triggers (desktop brand pills). -suggest: - keywords: - - customer.io - hosts: - - customer.io - -post_install: | - On first connection Hermes opens a browser to authorize with - Customer.io (or run `hermes mcp login customer-io`). Approve access, - then restart the session so tools load. - - EU-region workspaces: change mcp_servers.customer-io.url to - https://mcp-eu.customer.io/mcp in config.yaml. diff --git a/optional-mcps/dropbox/manifest.yaml b/optional-mcps/dropbox/manifest.yaml index 38b6a31fd1..f1df12d14f 100644 --- a/optional-mcps/dropbox/manifest.yaml +++ b/optional-mcps/dropbox/manifest.yaml @@ -19,6 +19,14 @@ transport: auth: type: oauth +# Excluded: account quota probe and the niche file-request feature trio. +tools: + default_excluded: + - GetUsageAndQuota + - CreateFileRequest + - GetFileRequest + - ListFileRequests + # Composer-suggestion triggers (desktop brand pills). suggest: keywords: diff --git a/optional-mcps/fireflies/manifest.yaml b/optional-mcps/fireflies/manifest.yaml index a93f7b4ab9..164dd7b87f 100644 --- a/optional-mcps/fireflies/manifest.yaml +++ b/optional-mcps/fireflies/manifest.yaml @@ -19,6 +19,13 @@ transport: auth: type: oauth +# Excluded: experimental ChatGPT-connector search/fetch shims duplicating +# fireflies_get_transcripts / fireflies_get_transcript + get_summary. +tools: + default_excluded: + - fireflies_search + - fireflies_fetch + # Composer-suggestion triggers (desktop brand pills). suggest: keywords: diff --git a/optional-mcps/gamma/manifest.yaml b/optional-mcps/gamma/manifest.yaml index 23cf1820a4..4968a14d69 100644 --- a/optional-mcps/gamma/manifest.yaml +++ b/optional-mcps/gamma/manifest.yaml @@ -19,6 +19,14 @@ transport: auth: type: oauth +# Excluded: per-person viewer tracking (incl. emails) — privacy-sensitive +# telemetry-grade analytics; get_gamma_analytics covers the useful case. +tools: + default_excluded: + - get_gamma_viewer_analytics + - get_gamma_viewer_detail_analytics + - get_gamma_card_analytics + # Composer-suggestion triggers (desktop brand pills). suggest: keywords: diff --git a/optional-mcps/gitlab/manifest.yaml b/optional-mcps/gitlab/manifest.yaml index 2c52505018..d196210626 100644 --- a/optional-mcps/gitlab/manifest.yaml +++ b/optional-mcps/gitlab/manifest.yaml @@ -19,6 +19,12 @@ transport: auth: type: oauth +# Excluded: version probe and Duo-product session listing. +tools: + default_excluded: + - get_mcp_server_version + - list_duo_sessions + # Composer-suggestion triggers (desktop brand pills). suggest: keywords: diff --git a/optional-mcps/globalping/manifest.yaml b/optional-mcps/globalping/manifest.yaml index ed08c9681e..6ace1971fd 100644 --- a/optional-mcps/globalping/manifest.yaml +++ b/optional-mcps/globalping/manifest.yaml @@ -19,6 +19,13 @@ transport: auth: type: oauth +# Excluded: in-band documentation/usage-guide/rate-limit probes. +tools: + default_excluded: + - help + - compareLocations + - limits + # Composer-suggestion triggers (desktop brand pills). suggest: keywords: diff --git a/optional-mcps/kiwi/manifest.yaml b/optional-mcps/kiwi/manifest.yaml index b4d3a020e2..bcd76a9c90 100644 --- a/optional-mcps/kiwi/manifest.yaml +++ b/optional-mcps/kiwi/manifest.yaml @@ -17,6 +17,13 @@ transport: auth: type: none +# The server ships exactly two tools: search-flight (the product) and +# feedback-to-devs (outbound feedback channel — excluded per Hermes policy: +# no telemetry/feedback tools without explicit user opt-in). +tools: + default_enabled: + - search-flight + # Composer-suggestion triggers (desktop brand pills). suggest: keywords: diff --git a/optional-mcps/klaviyo/manifest.yaml b/optional-mcps/klaviyo/manifest.yaml index 9bccffc31b..34d64863eb 100644 --- a/optional-mcps/klaviyo/manifest.yaml +++ b/optional-mcps/klaviyo/manifest.yaml @@ -14,7 +14,11 @@ source: https://developers.klaviyo.com/en/docs/klaviyo_mcp_server transport: type: http - url: https://mcp.klaviyo.com/mcp + # Vendor-documented debloat params: core-tools-only trims the 262-tool + # surface to ~40 core tools; disable-tools-with-user-generated-content + # removes tools that read UGC (vendor's prompt-injection mitigation). + # Drop the params in mcp_servers.klaviyo.url for the full surface. + url: https://mcp.klaviyo.com/mcp?core-tools-only=true&disable-tools-with-user-generated-content=true auth: type: oauth diff --git a/optional-mcps/miro/manifest.yaml b/optional-mcps/miro/manifest.yaml index 09166ce83b..20e4040877 100644 --- a/optional-mcps/miro/manifest.yaml +++ b/optional-mcps/miro/manifest.yaml @@ -19,6 +19,17 @@ transport: auth: type: oauth +# Excluded: diagram_create/diagram_get_dsl are vendor-deprecated; the four +# layout_* tools are 'deprecating soon', duplicated by the canvas_* set. +tools: + default_excluded: + - diagram_create + - diagram_get_dsl + - layout_create + - layout_get_dsl + - layout_read + - layout_update + # Composer-suggestion triggers (desktop brand pills). suggest: keywords: diff --git a/optional-mcps/mixpanel/manifest.yaml b/optional-mcps/mixpanel/manifest.yaml index 6dbfa4bc0e..d1251d6314 100644 --- a/optional-mcps/mixpanel/manifest.yaml +++ b/optional-mcps/mixpanel/manifest.yaml @@ -19,6 +19,22 @@ transport: auth: type: oauth +# Excluded: six guidance pseudo-tools returning static best-practice text; +# chart-widget renderer; deep-link generator; bulk variants of +# Edit-Event/Edit-Property. +tools: + default_excluded: + - Get-Experiment-Setup-Guidance + - Get-Experiment-Results-Interpretation-Guidance + - Explain-Experiment-Health-Check + - Run-Experiment-Pre-Launch-Checks + - Get-Feature-Flag-Setup-Guidance + - Get-Feature-Flag-Lifecycle-Guidance + - Display-Query + - Get-Lexicon-URL + - Bulk-Edit-Events + - Bulk-Edit-Properties + # Composer-suggestion triggers (desktop brand pills). suggest: keywords: diff --git a/optional-mcps/monday/manifest.yaml b/optional-mcps/monday/manifest.yaml index fb6ac7d55d..06ab21eca7 100644 --- a/optional-mcps/monday/manifest.yaml +++ b/optional-mcps/monday/manifest.yaml @@ -19,6 +19,18 @@ transport: auth: type: oauth +# Excluded: the 'Advanced API access' trio is a generic execute-any-GraphQL +# escape hatch (meta-layer — Hermes policy: no server-side API-execute +# indirection); get_sprint_summary is an AI-product feature; +# create_notification pings other users' bell/email. +tools: + default_excluded: + - all_monday_api + - get_graphql_schema + - get_type_details + - get_sprint_summary + - create_notification + # Composer-suggestion triggers (desktop brand pills). suggest: keywords: diff --git a/optional-mcps/motherduck/manifest.yaml b/optional-mcps/motherduck/manifest.yaml index 5baed20bdf..6c8c3d1d3a 100644 --- a/optional-mcps/motherduck/manifest.yaml +++ b/optional-mcps/motherduck/manifest.yaml @@ -19,6 +19,21 @@ transport: auth: type: oauth +# Curated default: the 9 core catalog/SQL tools. The other 30 (Dive, Flight +# scheduled-jobs, Guide products + ask_docs_question) stay available via +# `hermes mcp configure motherduck`. +tools: + default_enabled: + - list_columns + - list_databases + - list_macros + - list_shares + - list_tables + - list_views + - query + - query_rw + - search_catalog + # Composer-suggestion triggers (desktop brand pills). suggest: keywords: diff --git a/optional-mcps/neon/manifest.yaml b/optional-mcps/neon/manifest.yaml index ed5efab8c9..8ba6da416c 100644 --- a/optional-mcps/neon/manifest.yaml +++ b/optional-mcps/neon/manifest.yaml @@ -19,6 +19,22 @@ transport: auth: type: oauth +# Excluded: search/fetch nav indirection (redundant with list/describe +# tools); docs-lookup pair; observability beta (single-region, dead weight +# for most); Neon Auth product provisioning trio. +tools: + default_excluded: + - search + - fetch + - list_docs_resources + - get_doc_resource + - query_logs + - list_log_fields + - list_log_field_values + - provision_neon_auth + - configure_neon_auth + - get_neon_auth_config + # Composer-suggestion triggers (desktop brand pills). suggest: keywords: diff --git a/optional-mcps/omnisend/manifest.yaml b/optional-mcps/omnisend/manifest.yaml deleted file mode 100644 index 62ce1f2164..0000000000 --- a/optional-mcps/omnisend/manifest.yaml +++ /dev/null @@ -1,32 +0,0 @@ -# Nous-approved MCP catalog entry. -# Presence in this directory = approval. Merged via PR review. -manifest_version: 1 - -name: omnisend -description: 'Omnisend: ecommerce email/SMS campaigns, flows, and segments.' -source: https://api-docs.omnisend.com/v2026-preview/reference/mcp-server-v2 - -# Official vendor-hosted remote MCP (URL-only — Hermes never spawns a local -# process for this entry). Native OAuth 2.1 + Dynamic Client Registration -# (verified live: RFC 9728 protected-resource metadata -> AS metadata with -# registration_endpoint); Hermes's MCP client + mcp_oauth_manager handle -# discovery, PKCE, token exchange, and refresh. - -transport: - type: http - url: https://mcp.omnisend.com/v2/mcp - -auth: - type: oauth - -# Composer-suggestion triggers (desktop brand pills). -suggest: - keywords: - - omnisend - hosts: - - omnisend.com - -post_install: | - On first connection Hermes opens a browser to authorize with - Omnisend (or run `hermes mcp login omnisend`). Approve access, - then restart the session so tools load. diff --git a/optional-mcps/plaid/manifest.yaml b/optional-mcps/plaid/manifest.yaml index 3b7e27c95d..281a434cb6 100644 --- a/optional-mcps/plaid/manifest.yaml +++ b/optional-mcps/plaid/manifest.yaml @@ -19,6 +19,11 @@ transport: auth: type: oauth +# Excluded: meta-intro tool that spends a call explaining the other four. +tools: + default_excluded: + - plaid_get_tools_introduction + # Composer-suggestion triggers (desktop brand pills). suggest: keywords: diff --git a/optional-mcps/postman/manifest.yaml b/optional-mcps/postman/manifest.yaml index 09f5247179..bd0beb4311 100644 --- a/optional-mcps/postman/manifest.yaml +++ b/optional-mcps/postman/manifest.yaml @@ -14,7 +14,10 @@ source: https://learning.postman.com/docs/reference/postman-api/postman-mcp-serv transport: type: http - url: https://mcp.postman.com/mcp + # /minimal is Postman's own documented essential-CRUD variant (collections, + # workspaces, environments). The Full variant at /mcp is 100+ tools with + # Enterprise surface; switch mcp_servers.postman.url if you need it. + url: https://mcp.postman.com/minimal auth: type: oauth diff --git a/optional-mcps/prisma-postgres/manifest.yaml b/optional-mcps/prisma-postgres/manifest.yaml index 13330afb54..e90ab17c79 100644 --- a/optional-mcps/prisma-postgres/manifest.yaml +++ b/optional-mcps/prisma-postgres/manifest.yaml @@ -19,6 +19,11 @@ transport: auth: type: oauth +# Excluded: docs Q&A tool bundled into a DB-management server. +tools: + default_excluded: + - search_prisma_documentation + # Composer-suggestion triggers (desktop brand pills). suggest: keywords: diff --git a/optional-mcps/ramp/manifest.yaml b/optional-mcps/ramp/manifest.yaml deleted file mode 100644 index 9e89aa7406..0000000000 --- a/optional-mcps/ramp/manifest.yaml +++ /dev/null @@ -1,36 +0,0 @@ -# Nous-approved MCP catalog entry. -# Presence in this directory = approval. Merged via PR review. -manifest_version: 1 - -name: ramp -description: 'Spend management: transactions, cards, reimbursements.' -source: https://docs.ramp.com/developer-api/v1/guides/ramp-mcp-remote - -# Official vendor-hosted remote MCP (URL-only — Hermes never spawns a local -# process for this entry). Native OAuth 2.1 + Dynamic Client Registration -# (verified live: RFC 9728 protected-resource metadata -> AS metadata with -# registration_endpoint); Hermes's MCP client + mcp_oauth_manager handle -# discovery, PKCE, token exchange, and refresh. - -transport: - type: http - url: https://mcp.ramp.com/mcp - -auth: - type: oauth - -# Composer-suggestion triggers (desktop brand pills). -suggest: - keywords: - - ramp - - expenses - hosts: - - ramp.com - -post_install: | - On first connection Hermes opens a browser to authorize with - Ramp (or run `hermes mcp login ramp`). Approve access, - then restart the session so tools load. - - Multi-entity businesses use https://mcp.ramp.com//mcp — - override mcp_servers.ramp.url in config.yaml if needed. diff --git a/optional-mcps/robinhood/manifest.yaml b/optional-mcps/robinhood/manifest.yaml index 1c67c1f479..b110aa95b6 100644 --- a/optional-mcps/robinhood/manifest.yaml +++ b/optional-mcps/robinhood/manifest.yaml @@ -19,6 +19,16 @@ transport: auth: type: oauth +# Excluded: options-tier upsell link and social watchlist engagement +# features. Trading tools stay enabled by design — see the post_install +# caution. +tools: + default_excluded: + - get_option_level_upgrade_info + - get_popular_watchlists + - follow_watchlist + - unfollow_watchlist + # Composer-suggestion triggers (desktop brand pills). suggest: keywords: diff --git a/optional-mcps/semgrep/manifest.yaml b/optional-mcps/semgrep/manifest.yaml index d109de2e6b..523e026657 100644 --- a/optional-mcps/semgrep/manifest.yaml +++ b/optional-mcps/semgrep/manifest.yaml @@ -19,6 +19,15 @@ transport: auth: type: oauth +# Excluded: security_check duplicates semgrep_scan; static metadata and +# schema probes. (Vendor archived the standalone repo — live surface may +# drift; excludes no-op harmlessly if names change.) +tools: + default_excluded: + - security_check + - supported_languages + - semgrep_rule_schema + # Composer-suggestion triggers (desktop brand pills). suggest: keywords: diff --git a/optional-mcps/todoist/manifest.yaml b/optional-mcps/todoist/manifest.yaml index d390018eb5..a662a6ded5 100644 --- a/optional-mcps/todoist/manifest.yaml +++ b/optional-mcps/todoist/manifest.yaml @@ -19,6 +19,15 @@ transport: auth: type: oauth +# Excluded: search/fetch are the OpenAI-connector compatibility layer that +# duplicates the find-* tools; template import/export is niche. +tools: + default_excluded: + - search + - fetch + - export-project-template + - import-project-template + # Composer-suggestion triggers (desktop brand pills). suggest: keywords: diff --git a/optional-mcps/wix/manifest.yaml b/optional-mcps/wix/manifest.yaml deleted file mode 100644 index fea589e303..0000000000 --- a/optional-mcps/wix/manifest.yaml +++ /dev/null @@ -1,32 +0,0 @@ -# Nous-approved MCP catalog entry. -# Presence in this directory = approval. Merged via PR review. -manifest_version: 1 - -name: wix -description: Manage Wix sites, stores, bookings, and CMS content. -source: https://dev.wix.com/docs/sdk/articles/use-the-wix-mcp/about-the-wix-mcp - -# Official vendor-hosted remote MCP (URL-only — Hermes never spawns a local -# process for this entry). Native OAuth 2.1 + Dynamic Client Registration -# (verified live: RFC 9728 protected-resource metadata -> AS metadata with -# registration_endpoint); Hermes's MCP client + mcp_oauth_manager handle -# discovery, PKCE, token exchange, and refresh. - -transport: - type: http - url: https://mcp.wix.com/mcp - -auth: - type: oauth - -# Composer-suggestion triggers (desktop brand pills). -suggest: - keywords: - - wix - hosts: - - wix.com - -post_install: | - On first connection Hermes opens a browser to authorize with - Wix (or run `hermes mcp login wix`). Approve access, - then restart the session so tools load. diff --git a/optional-mcps/zapier/manifest.yaml b/optional-mcps/zapier/manifest.yaml deleted file mode 100644 index b1571dab26..0000000000 --- a/optional-mcps/zapier/manifest.yaml +++ /dev/null @@ -1,36 +0,0 @@ -# Nous-approved MCP catalog entry. -# Presence in this directory = approval. Merged via PR review. -manifest_version: 1 - -name: zapier -description: Trigger actions across 8,000+ apps via Zapier. -source: https://zapier.com/mcp - -# Official vendor-hosted remote MCP (URL-only — Hermes never spawns a local -# process for this entry). Native OAuth 2.1 + Dynamic Client Registration -# (verified live: RFC 9728 protected-resource metadata -> AS metadata with -# registration_endpoint); Hermes's MCP client + mcp_oauth_manager handle -# discovery, PKCE, token exchange, and refresh. - -transport: - type: http - url: https://mcp.zapier.com/api/mcp/mcp - -auth: - type: oauth - -# Composer-suggestion triggers (desktop brand pills). -suggest: - keywords: - - zapier - - automation - hosts: - - zapier.com - -post_install: | - On first connection Hermes opens a browser to authorize with - Zapier (or run `hermes mcp login zapier`). Approve access, - then restart the session so tools load. - - Pick which apps/actions the agent may use at mcp.zapier.com after - connecting.