fix(mcp): retire the n8n bridge catalog entry (#116048)

Stop offering the third-party bridge for new catalog installs. Existing
connections keep their saved transport, credentials, and tool selection;
the runtime and configured-server controls do not require a manifest.

Update CLI examples and document that catalog reinstall is unavailable.
Adding n8n's official server remains separate work.
This commit is contained in:
Siddharth Balyan
2026-09-19 17:51:30 +05:30
committed by GitHub
parent 7c6f21a5e1
commit 8d4abc3ea6
4 changed files with 14 additions and 87 deletions

View File

@@ -72,7 +72,7 @@ def build_mcp_parser(subparsers, *, cmd_mcp: Callable) -> None:
"picker", help="Interactive catalog picker (also the default for `hermes mcp`)")
mcp_sub.add_parser("catalog", help="List Nous-approved MCPs available for one-click install")
mcp_install_p = mcp_sub.add_parser(
"install", help="Install a catalog MCP by name (e.g. `hermes mcp install n8n`)")
"install", help="Install a catalog MCP by name (e.g. `hermes mcp install deepwiki`)")
mcp_install_p.add_argument("identifier", help="Catalog entry name (or `official/<name>`)")
add_accept_hooks_flag(mcp_parser)

View File

@@ -1,81 +0,0 @@
# Nous-approved MCP catalog entry.
# Presence in this directory = approval. Merged via PR review.
#
# Schema version 1.
manifest_version: 1
name: n8n
description: Manage and inspect n8n workflows from Hermes (stdio bridge, no public port).
source: https://github.com/CyberSamuraiX/hermes-n8n-mcp
# How to launch the server once installed. The keys here map 1:1 to the
# `mcp_servers.<name>` block written into ~/.hermes/config.yaml by the
# existing `_save_mcp_server()` helper in hermes_cli/mcp_config.py.
transport:
type: stdio
# For git-installed servers, ${INSTALL_DIR} is substituted at install time
# with the path the catalog cloned the repo into. The catalog never
# auto-updates: the user re-runs `hermes mcp install official/n8n` to
# refresh.
command: "${INSTALL_DIR}/.venv/bin/python"
args:
- "${INSTALL_DIR}/server.py"
# Optional install step. Omit for npm/uvx servers where transport.command
# is the install (`npx -y package`). Use for repos that need a local clone
# + dependency install.
install:
type: git
url: https://github.com/CyberSamuraiX/hermes-n8n-mcp.git
# Pinned per catalog dependency policy: full commit SHA (branches and tags
# can be moved; SHAs cannot), and the pinned commit must be at least
# 2 weeks old at pin time — same supply-chain rules as pyproject
# dependencies. This SHA is "feat: add local n8n MCP bridge for Hermes"
# (2026-05-23). Bumping the pin is a PR to this manifest.
ref: 7a9ae00795593aa1fdb4e61ecd640e8bfd0c3841
# Bootstrap commands run inside the cloned directory after clone.
bootstrap:
- "python3 -m venv .venv"
- ".venv/bin/pip install -r requirements.txt"
# Authentication. Three shapes:
# type: api_key — prompt for env vars, write to ~/.hermes/.env
# type: oauth — provider-mediated or remote MCP native OAuth (case 1/2)
# type: none — no credentials needed
auth:
type: api_key
env:
- name: N8N_BASE_URL
prompt: "n8n instance URL"
default: "http://127.0.0.1:5678"
required: true
secret: false
- name: N8N_API_KEY
prompt: "n8n API key (generate under Settings → API)"
required: true
secret: true
# Tool selection at install time:
# n8n's bridge exposes 11 tools. Mutating ones (activate/deactivate, docker
# container_logs) are pruned from the default so a user who installs casually
# gets a read-mostly safe surface. Users see the full list in the install-time
# checklist and can opt into the mutating tools per their threat model.
tools:
default_enabled:
- health
- list_workflows
- get_workflow
- find_workflows
- list_executions
- get_execution
- recent_failures
- export_workflow
post_install: |
The n8n bridge expects to talk to a running n8n instance over the URL you
provided. Generate an API key in n8n under Settings → API.
Workflow activate/deactivate calls are real mutations against your live n8n.
Treat them carefully.
Start a new Hermes session to load the n8n tools.

View File

@@ -1534,7 +1534,7 @@ Manage MCP (Model Context Protocol) server configurations and run Hermes as an M
|------------|-------------|
| *(none)* or `picker` | Interactive catalog picker — browse Nous-approved MCPs and install/enable/disable. |
| `catalog` | List Nous-approved MCPs (plain text, scriptable). |
| `install <name>` | Install a catalog entry (e.g. `hermes mcp install n8n`). |
| `install <name>` | Install a catalog entry (e.g. `hermes mcp install deepwiki`). |
| `serve [-v\|--verbose]` | Run Hermes as an MCP server — expose conversations to other agents. |
| `add <name> [--url URL] [--command CMD] [--auth oauth\|header] [--args ...]` | Add a custom MCP server with automatic tool discovery. `--args` passes the remaining argv to the stdio command, so put it last. |
| `remove <name>` (alias: `rm`) | Remove an MCP server from config. |

View File

@@ -63,15 +63,15 @@ the chat, and Install writes the same config the CLI would. On the CLI and in
messaging apps the agent relays the commands below instead.
```bash
hermes mcp # interactive picker (default)
hermes mcp catalog # plain-text list, scriptable
hermes mcp install n8n # install a catalog entry by name
hermes mcp # interactive picker (default)
hermes mcp catalog # plain-text list, scriptable
hermes mcp install deepwiki # install a catalog entry by name
```
The picker shows each entry with its current status:
```
n8n available Manage and inspect n8n workflows from Hermes
deepwiki available Ask questions about public GitHub repositories
linear enabled Linear issue/project management (remote OAuth)
github installed (disabled) GitHub repo + PR tools
```
@@ -82,6 +82,14 @@ enable, disable, or uninstall. Catalog entries are stored under
Nous approval. There is no community submission tier; entries are added by
merging a PR.
The third-party n8n bridge is no longer available for catalog installation.
Existing installations keep their `mcp_servers` configuration, credentials,
installed files, and selected tools. They continue to load as configured MCP
servers and appear as custom entries in the picker, where you can still
configure tools or enable and disable them. Catalog reinstall is no longer
available. This change does not migrate existing connections to
[n8n's official MCP server](https://docs.n8n.io/connect/connect-to-n8n-mcp-server/).
Catalog entries can require:
- **API key** — Hermes prompts at install time and writes the value to