fix(tools): restore setup_mcp's never-hand-edit instruction

9d9f44d638 removed the desktop platform hint's "never hand-edit
mcp_servers config for them" sentence, reasoning it was a "word-for-word
duplicate of the setup_mcp tool schema... taught on every call." The
schema has never contained that instruction — only "never re-ask after
a decline." setup_mcp is desktop_ui-toolset-only and no runtime guard
in agent/file_safety.py covers mcp_servers config, so removing the only
place teaching this left a real gap: a model asked to add/configure an
MCP server could just write_file into mcp_servers config directly,
bypassing the consent-card/OAuth flow the tool exists to enforce.

Restored the instruction directly in SETUP_MCP_SCHEMA's description —
completing the original commit's stated intent (move it to the schema)
rather than reverting to the platform hint, since the schema reaches
every setup_mcp call regardless of platform hint wording changes.

Added a regression test asserting the schema description forbids
hand-editing mcp_servers config, so a future prompt-diet pass can't
silently drop it again without a test failing.
This commit is contained in:
nftpoetrist
2026-08-30 02:00:52 +03:00
committed by Teknium
parent bc81d0a665
commit d6a6d87c4a
2 changed files with 11 additions and 2 deletions

View File

@@ -11,7 +11,15 @@ import json
import pytest
from tools.setup_mcp_tool import setup_mcp_tool
from tools.setup_mcp_tool import SETUP_MCP_SCHEMA, setup_mcp_tool
def test_schema_forbids_hand_editing_mcp_servers_config():
# Nothing else teaches the model this: the tool is desktop_ui-only, so
# without it a model could just write_file into mcp_servers config
# directly, bypassing the consent-card/OAuth flow this tool exists for.
assert "hand-edit" in SETUP_MCP_SCHEMA["description"]
assert "mcp_servers" in SETUP_MCP_SCHEMA["description"]
def test_requires_desktop_callback():

View File

@@ -77,7 +77,8 @@ SETUP_MCP_SCHEMA = {
"Propose an MCP server as an inline consent card (install a catalog "
"entry, re-enable a disabled server, or run OAuth); blocks until the "
"user acts. Use when they ask to add an MCP or a task clearly needs "
"a missing one. Never re-ask after a decline — on declined/"
"a missing one. Never hand-edit mcp_servers config for them — always "
"use this tool. Never re-ask after a decline — on declined/"
"unanswered, continue without it. Catalog names: `hermes mcp "
"catalog` in the terminal."
),