fix(mcp): declare readOnly/destructive/openWorld hints on every listed tool - #1774
Merged
Merged
Conversation
📊 Code coverage
Gate: line coverage must stay at or above the threshold. Ratchet plan (W21): Backend → 55%, CLI → 50%, Frontend → 30% by quarter end. |
…d tool OpenAI plugin review rejects MCP servers whose tools omit explicit boolean readOnlyHint, destructiveHint and openWorldHint annotations; NyxID's tools/list sent only name, description and inputSchema, so all 14 nyx__ meta-tools failed the portal scan. tools/list now attaches MCP annotations from mcp_service::tool_annotations: meta-tools use a fixed table (discovery/read tools read-only, connect and oracle submissions open-world writes, nyx__call_tool and nyx__ssh_exec destructive), and per-service tools derive hints from their HTTP method (GET/HEAD/OPTIONS read-only, POST non-destructive write, other methods and generic proxies destructive). No stored data or request handling changes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ctkm-aelf
force-pushed
the
fix/mcp-tool-annotations
branch
from
October 5, 2026 10:00
a3e88b3 to
564f0aa
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
readOnlyHint,destructiveHintandopenWorldHintannotations, andtools/listonly sentname,descriptionandinputSchema(42 findings across the 14nyx__*meta-tools).tools/listnow attaches MCPannotationsfrom a newmcp_service::tool_annotations:search_tools,discover_services,list_connected_services,wait_for_connection,ssh_list_services,oracle_pools/result/session) are read-only;connect_serviceandoracle_ask/attach/extractare open-world writes;call_toolandssh_execare destructive.Test Plan
tool_annotations_cover_every_meta_tool_with_boolean_hints,tool_annotations_follow_service_endpoint_methodcargo test -p nyxid -- tool_annotations mcp_transport::tests→ 76 passed (with local MongoDB)cargo clippy -p nyxid --all-targets -- -D warningsclean;cargo fmtcleanChecklist
Follow-up (not in this PR): OpenAI's plugin guidelines disallow "a generic executor to enable operations not individually exposed for review", which
nyx__search_tools+nyx__call_toolmay trip at human review.🤖 Generated with Claude Code