Skip to content

fix(mcp): declare readOnly/destructive/openWorld hints on every listed tool - #1774

Merged
ctkm-aelf merged 2 commits into
mainfrom
fix/mcp-tool-annotations
Oct 6, 2026
Merged

ctkm-aelf merged 2 commits into
mainfrom
fix/mcp-tool-annotations

Conversation

@ctkm-aelf

Copy link
Copy Markdown
Collaborator

Summary

  • OpenAI's plugin portal scan rejects NyxID's MCP server: every listed tool must declare explicit boolean readOnlyHint, destructiveHint and openWorldHint annotations, and tools/list only sent name, description and inputSchema (42 findings across the 14 nyx__* meta-tools).
  • tools/list now attaches MCP annotations from a new mcp_service::tool_annotations:
    • Meta-tools use a fixed table: discovery/read tools (search_tools, discover_services, list_connected_services, wait_for_connection, ssh_list_services, oracle_pools/result/session) are read-only; connect_service and oracle_ask/attach/extract are open-world writes; call_tool and ssh_exec are destructive.
    • Per-service tools derive hints from their HTTP method (GET/HEAD/OPTIONS read-only, POST non-destructive write, other methods and generic proxies destructive).
  • Response shape is additive only; no stored data, auth, or request handling changes.

Test Plan

  • New tests: tool_annotations_cover_every_meta_tool_with_boolean_hints, tool_annotations_follow_service_endpoint_method
  • cargo test -p nyxid -- tool_annotations mcp_transport::tests → 76 passed (with local MongoDB)
  • cargo clippy -p nyxid --all-targets -- -D warnings clean; cargo fmt clean
  • After deploy: rerun the OpenAI plugin portal MCP scan and confirm the annotation findings are gone

Checklist

  • Code follows the project's architecture rules
  • No hardcoded secrets or credentials
  • Error messages do not leak internal details
  • Documentation updated (if applicable) — n/a

Follow-up (not in this PR): OpenAI's plugin guidelines disallow "a generic executor to enable operations not individually exposed for review", which nyx__search_tools + nyx__call_tool may trip at human review.

🤖 Generated with Claude Code

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

📊 Code coverage

Component Lines Threshold Status Δ vs base
Backend (nyxid) 87.07% 73% ✅ 🔺 +0.02

Gate: line coverage must stay at or above the threshold. Ratchet plan (W21): Backend → 55%, CLI → 50%, Frontend → 30% by quarter end.

ctkm-aelf and others added 2 commits October 5, 2026 17:35
…d tool

OpenAI plugin review rejects MCP servers whose tools omit explicit boolean
readOnlyHint, destructiveHint and openWorldHint annotations; NyxID's
tools/list sent only name, description and inputSchema, so all 14 nyx__
meta-tools failed the portal scan.

tools/list now attaches MCP annotations from mcp_service::tool_annotations:
meta-tools use a fixed table (discovery/read tools read-only, connect and
oracle submissions open-world writes, nyx__call_tool and nyx__ssh_exec
destructive), and per-service tools derive hints from their HTTP method
(GET/HEAD/OPTIONS read-only, POST non-destructive write, other methods and
generic proxies destructive). No stored data or request handling changes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ctkm-aelf
ctkm-aelf force-pushed the fix/mcp-tool-annotations branch from a3e88b3 to 564f0aa Compare October 5, 2026 10:00
@ctkm-aelf
ctkm-aelf merged commit 6de2041 into main Oct 6, 2026
37 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant