Repository navigation
feat(policy): give [policy] a say over MCP servers, and show the matrix in doctor - #109
Merged
Merged
Conversation
…ix in doctor An org allowlist that could not say "no MCP servers" was incomplete: a declared server is the largest surface a skill can request — third-party code running with the agent's permissions. `deny_mcp = true` refuses any skill declaring one. `allow_mcp_servers` takes the same globs as allow_sources and matches a server's command line (stdio) or url (remote), so an org can pin servers to its own registry instead of banning MCP outright. Both are enforced at install and rechecked by doctor, like every other policy rule. doctor now prints the MCP support matrix whenever a skill declares a server: which targets carry it and to which file, and for the eight that cannot, the specific reason. That only surfaced as a compile warning before — after the decision to install had already been made. Also removes two exports added in 0.19.0 that nothing called (isWholeRef, and the needlessly public MCP_TARGETS). Adds 7 tests. 0.19.1.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-through on 0.19.0.
Policy
An org allowlist that couldn't say "no MCP servers" was incomplete — a declared server is the largest surface a skill can request.
allow_mcp_serverstakes the same globs asallow_sourcesand matches a server's command line for stdio or url for remote. Enforced at install, rechecked bydoctor, like every other policy rule.Visibility
doctornow prints the MCP support matrix when a skill declares a server — which targets carry it and to which file, and for the eight that can't, the specific reason. Previously that only appeared as a compile warning, i.e. after you'd already decided to install.Cleanup
Removes two exports I added in 0.19.0 that nothing called (
isWholeRef, and the needlessly publicMCP_TARGETS).7 new tests; suite, typecheck, site
--checkand bench gate all green.