ci: pin both MCP tool surfaces with truecopy and gate them - #131
Merged
Merged
Conversation
scripts/dump-tools.mjs writes the tools/list response of the bridge MCP server and of fieldpass to mcp/, truecopy.lock pins both, and the truecopy gate workflow fails when the code no longer matches the manifest or the manifest no longer matches the lock.
sprayberry-redline
approved these changes
Sep 27, 2026
sprayberry-redline
left a comment
Collaborator
There was a problem hiding this comment.
Approved at 9b164d8.
The generator drives the real tools/list path of both servers through an in-memory MCP client, so the manifests cannot drift from what a connected agent would actually see; the bridge server's lazy rec.resolve() means the noConnect thrower is never reached during listing, and createPicketServer({ judge: null, cdp: null }) builds a GovernedBrowser with no network side effects. Ordering the workflow as dump-tools.mjs --check then truecopy verify gives the code -> manifest -> lock chain a failure at the first broken link, and the new job passed at this head in 17s, which confirms both npm ci steps supply what the script imports.
Minor, non-blocking:
scripts/dump-tools.mjs:54: the character class upper bound is a raw U+FFFF byte sequence in the source rather than the escape\uffff. It works, but editors and diff tools tend to mangle or hide that byte; the escape form is safer to keep in the file.scripts/dump-tools.mjs:41:localeCompareon tool names is locale-sensitive. The current names never tie on an underscore versus a letter, so the output is stable today; a plaina.name < b.name ? -1 : 1comparison would keep the manifest byte-identical regardless of the runner's ICU locale.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
askalf/truecopy-action.mcp-server.mjsexposesbrowser_evaluate,browser_typeandbrowser_click, and fieldpass exposes thepicket_*gate tools. A tool description is text an agent reads and acts on, so a change to one now has to be regenerated and re-pinned on purpose, and it is poison-scanned when it is.scripts/dump-tools.mjsreads each server's realtools/listresponse through an MCP client over an in-memory transport and writesmcp/browser-bridge.jsonandmcp/fieldpass.json. Listing tools never opens a browser, because the bridge server connects on the first tool call.--checkfails if a committed manifest no longer matches the code.truecopy.lockpins both manifests (truecopy 0.10.4, redstamp 0.7.5, both clean).truecopy verifyfails on drift, or on the same bytes turning poisonous under a newer detector.\uescapes. The tool descriptions carry em dashes, whichcheck-hygiene.mjsrejects on added lines. The parsed JSON is the same.truecopy gateto the fleet-statusworkflow_runlist (the fleet-status test requires every pull_request workflow to be listed). Adds the new paths to themcplabel.What's NOT in this PR
truecopy gatea required check. That is a branch-rule change for the operator.Test plan
node scripts/dump-tools.mjs --check: both manifests match (9 tools each). This also passes with policy/ installed--omit=optional, the way CI installs it.truecopy scanon both manifests: clean.truecopy verify: 2 of 2 pinned verified.npm test129/129,node scripts/fleet-status.test.mjs97/97, actionlint clean,check-hygiene.mjs --range origin/master..HEADclean.truecopy gate / verify pinned tool surfacegreen.