Problem
None of RimSage's tools declare MCP tool annotations, so clients that restrict tools to read-only modes can't tell they're safe and block them.
In Devin (formerly Windsurf), local agent, Windows client, calling any RimSage tool in plan mode fails with:
MCP tool 'search_source' on server 'rimsage' is currently unavailable: only tools annotated as read-only (readOnlyHint) can be called in the current mode.
Devin's plan mode only allows MCP tools that set readOnlyHint: true. Other clients with read-only modes, such as Cursor's Ask mode, have the same restriction.
Cause
In src/server.ts, all six tools (search_source, read_file, list_directory, get_def_details, search_defs, read_csharp_symbol) are registered with only description and inputSchema. No annotations are set.
All six only query the prebuilt index and bundled sources, so they are read-only in practice.
Proposed fix
Declare the annotations on each tool. registerTool accepts an annotations field (ToolAnnotations), so a shared constant is enough:
const readOnlyAnnotations = { readOnlyHint: true, openWorldHint: false }
server.registerTool(
'search_source',
{
description: 'Search RimWorld source code using regex.',
annotations: readOnlyAnnotations,
inputSchema: z.object({ /* ... */ }),
},
// handler
)
openWorldHint: false also signals that the tools only touch the local index, not external systems.
This should be applied to the hosted mcp.rimsage.com endpoint as well, since that's the recommended way to use RimSage.
I tested this by self-hosting with readOnlyHint: true and openWorldHint: false added to all six tools. With that change, the tools work in Devin's plan mode.
Environment
- RimSage 1.0.2 (
package.json)
- Client: Devin local agent (Windows), plan mode
- Description written by Claude
Problem
None of RimSage's tools declare MCP tool annotations, so clients that restrict tools to read-only modes can't tell they're safe and block them.
In Devin (formerly Windsurf), local agent, Windows client, calling any RimSage tool in plan mode fails with:
Devin's plan mode only allows MCP tools that set
readOnlyHint: true. Other clients with read-only modes, such as Cursor's Ask mode, have the same restriction.Cause
In
src/server.ts, all six tools (search_source,read_file,list_directory,get_def_details,search_defs,read_csharp_symbol) are registered with onlydescriptionandinputSchema. Noannotationsare set.All six only query the prebuilt index and bundled sources, so they are read-only in practice.
Proposed fix
Declare the annotations on each tool.
registerToolaccepts anannotationsfield (ToolAnnotations), so a shared constant is enough:openWorldHint: falsealso signals that the tools only touch the local index, not external systems.This should be applied to the hosted
mcp.rimsage.comendpoint as well, since that's the recommended way to use RimSage.I tested this by self-hosting with
readOnlyHint: trueandopenWorldHint: falseadded to all six tools. With that change, the tools work in Devin's plan mode.Environment
package.json)