fix(tools): restore setup_mcp's never-hand-edit instruction
9d9f44d638 removed the desktop platform hint's "never hand-edit
mcp_servers config for them" sentence, reasoning it was a "word-for-word
duplicate of the setup_mcp tool schema... taught on every call." The
schema has never contained that instruction — only "never re-ask after
a decline." setup_mcp is desktop_ui-toolset-only and no runtime guard
in agent/file_safety.py covers mcp_servers config, so removing the only
place teaching this left a real gap: a model asked to add/configure an
MCP server could just write_file into mcp_servers config directly,
bypassing the consent-card/OAuth flow the tool exists to enforce.
Restored the instruction directly in SETUP_MCP_SCHEMA's description —
completing the original commit's stated intent (move it to the schema)
rather than reverting to the platform hint, since the schema reaches
every setup_mcp call regardless of platform hint wording changes.
Added a regression test asserting the schema description forbids
hand-editing mcp_servers config, so a future prompt-diet pass can't
silently drop it again without a test failing.
This commit is contained in:
@@ -11,7 +11,15 @@ import json
|
||||
|
||||
import pytest
|
||||
|
||||
from tools.setup_mcp_tool import setup_mcp_tool
|
||||
from tools.setup_mcp_tool import SETUP_MCP_SCHEMA, setup_mcp_tool
|
||||
|
||||
|
||||
def test_schema_forbids_hand_editing_mcp_servers_config():
|
||||
# Nothing else teaches the model this: the tool is desktop_ui-only, so
|
||||
# without it a model could just write_file into mcp_servers config
|
||||
# directly, bypassing the consent-card/OAuth flow this tool exists for.
|
||||
assert "hand-edit" in SETUP_MCP_SCHEMA["description"]
|
||||
assert "mcp_servers" in SETUP_MCP_SCHEMA["description"]
|
||||
|
||||
|
||||
def test_requires_desktop_callback():
|
||||
|
||||
@@ -77,7 +77,8 @@ SETUP_MCP_SCHEMA = {
|
||||
"Propose an MCP server as an inline consent card (install a catalog "
|
||||
"entry, re-enable a disabled server, or run OAuth); blocks until the "
|
||||
"user acts. Use when they ask to add an MCP or a task clearly needs "
|
||||
"a missing one. Never re-ask after a decline — on declined/"
|
||||
"a missing one. Never hand-edit mcp_servers config for them — always "
|
||||
"use this tool. Never re-ask after a decline — on declined/"
|
||||
"unanswered, continue without it. Catalog names: `hermes mcp "
|
||||
"catalog` in the terminal."
|
||||
),
|
||||
|
||||
Reference in New Issue
Block a user