diff --git a/tests/tools/test_setup_mcp_tool.py b/tests/tools/test_setup_mcp_tool.py index ae7be1d418..12842b6a71 100644 --- a/tests/tools/test_setup_mcp_tool.py +++ b/tests/tools/test_setup_mcp_tool.py @@ -11,7 +11,15 @@ import json import pytest -from tools.setup_mcp_tool import setup_mcp_tool +from tools.setup_mcp_tool import SETUP_MCP_SCHEMA, setup_mcp_tool + + +def test_schema_forbids_hand_editing_mcp_servers_config(): + # Nothing else teaches the model this: the tool is desktop_ui-only, so + # without it a model could just write_file into mcp_servers config + # directly, bypassing the consent-card/OAuth flow this tool exists for. + assert "hand-edit" in SETUP_MCP_SCHEMA["description"] + assert "mcp_servers" in SETUP_MCP_SCHEMA["description"] def test_requires_desktop_callback(): diff --git a/tools/setup_mcp_tool.py b/tools/setup_mcp_tool.py index 41f081735c..624540016b 100644 --- a/tools/setup_mcp_tool.py +++ b/tools/setup_mcp_tool.py @@ -77,7 +77,8 @@ SETUP_MCP_SCHEMA = { "Propose an MCP server as an inline consent card (install a catalog " "entry, re-enable a disabled server, or run OAuth); blocks until the " "user acts. Use when they ask to add an MCP or a task clearly needs " - "a missing one. Never re-ask after a decline — on declined/" + "a missing one. Never hand-edit mcp_servers config for them — always " + "use this tool. Never re-ask after a decline — on declined/" "unanswered, continue without it. Catalog names: `hermes mcp " "catalog` in the terminal." ),