Skip to content

feat(mcp): admit user MCP tools in Plan and Goal - #1384

Open
chengzhi-c wants to merge 9 commits into
vastsa:mainfrom
chengzhi-c:feat/plan-safe-mcp-tools
Open

chengzhi-c wants to merge 9 commits into
vastsa:mainfrom
chengzhi-c:feat/plan-safe-mcp-tools

Conversation

@chengzhi-c

@chengzhi-c chengzhi-c commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Plan and Goal can use user MCP tools named in each server's planSafeTools, or every active user MCP tool when the local allowMcpInPlanGoal switch is on.
  • The switch lives under Settings, AI, Permissions and stays on this installation. Portable sync does not export or apply it.
  • Each admitted tool carries only its own full name. Host admission requires that exact name, risk stays medium, and the raw tool name is what tools/call sends.
  • Saving only the tool list does not reconnect the server. A project server with the same id keeps its connection when the shadowed global list is saved.
  • Completing OAuth cannot reconnect a server whose configuration changed or was disabled while login was in progress.

Rebased onto current origin/main (831b66dfa). The per-server handshake timeout is preserved.

Verification

Checked locally at 913e8b611.

  • Desktop MCP admission, editor, permission, timeout, and settings round-trip tests
  • Desktop and agent-runtime typecheck, i18n parity, Biome, and style-token lint
  • Agent-runtime suite: 93 files, 1240 passed
  • Host MCP, permission, and config-sync tests, plus cargo fmt -p host-core --check
  • Host mcp_execution_forwards_the_admitted_raw_identity
  • cargo test -p host-core --locked: 745 passed. data_relocation fails the same two tests on current origin/main, and tools_abort_during_execution_kills_bash_and_cleans_registry passes on its own
  • Full apps/desktop node --test: the MCP files pass. The package run also hits pre-existing Windows failures (POSIX shell, SSH, macOS signing, models.dev catalog) and one Vite server that hangs in selection-tex
  • CI: the fork pull request is waiting for maintainer approval, so the workflows stop at action_required

Fixes #1112

A user MCP server stays out of Plan and Goal unless its record names the raw tools. The launch path forwards each named tool as its own full name, and host-core admits an mcp_ call only when that list contains the exact tool name. An empty list, a wildcard, and a sibling tool stay denied. Agent mode is unchanged.
Use native path basenames in fork assertions so Windows checks retain
their exact file-preservation contract.

Bound SDK-heavy test workers to available CPUs and at most four to
avoid resource starvation without increasing test timeouts.
Avoid forced handshakes for metadata edits. Isolate global MCP test
storage so sync clearing is verified against an independent target.
Raw MCP identities must not change underneath admitted tools after a
configuration update or reconnect. Unchanged editor arguments and local
permission preferences must survive saves and portable configuration sync.
Authorization completion used the record captured when login started. A configuration change or disable during the wait could reconnect that old server. Look up the current record and refuse the handshake when it no longer matches.
# Conflicts:
#	apps/desktop/src/components/extensions/McpEditorSheet.tsx
#	apps/desktop/test/user-mcp.test.mjs
#	crates/host-core/src/mcp_servers.rs
#	crates/host-core/src/mcp_servers/tests.rs
#	crates/host-core/src/rpc/mod.rs
#	packages/shared/src/types/capabilities.ts

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Feature Request: 建议支持通过配置指定 Plan/Goal 模式下的安全 MCP 工具

1 participant