Skip to content

feat(policy): give [policy] a say over MCP servers, and show the matrix in doctor - #109

Merged
singhharsh1708 merged 1 commit into
mainfrom
feat/mcp-policy
Aug 9, 2026
Merged

singhharsh1708 merged 1 commit into
mainfrom
feat/mcp-policy

Conversation

@singhharsh1708

Copy link
Copy Markdown
Owner

Follow-through on 0.19.0.

Policy

An org allowlist that couldn't say "no MCP servers" was incomplete — a declared server is the largest surface a skill can request.

[policy]
deny_mcp = true                                       # refuse any skill declaring a server
allow_mcp_servers = ["https://mcp.your-org.com/*"]    # or pin them to your own registry

allow_mcp_servers takes the same globs as allow_sources and matches a server's command line for stdio or url for remote. Enforced at install, rechecked by doctor, like every other policy rule.

Visibility

doctor now prints the MCP support matrix when a skill declares a server — which targets carry it and to which file, and for the eight that can't, the specific reason. Previously that only appeared as a compile warning, i.e. after you'd already decided to install.

Cleanup

Removes two exports I added in 0.19.0 that nothing called (isWholeRef, and the needlessly public MCP_TARGETS).

7 new tests; suite, typecheck, site --check and bench gate all green.

…ix in doctor

An org allowlist that could not say "no MCP servers" was incomplete: a
declared server is the largest surface a skill can request — third-party
code running with the agent's permissions.

`deny_mcp = true` refuses any skill declaring one. `allow_mcp_servers` takes
the same globs as allow_sources and matches a server's command line (stdio)
or url (remote), so an org can pin servers to its own registry instead of
banning MCP outright. Both are enforced at install and rechecked by doctor,
like every other policy rule.

doctor now prints the MCP support matrix whenever a skill declares a server:
which targets carry it and to which file, and for the eight that cannot, the
specific reason. That only surfaced as a compile warning before — after the
decision to install had already been made.

Also removes two exports added in 0.19.0 that nothing called (isWholeRef,
and the needlessly public MCP_TARGETS).

Adds 7 tests. 0.19.1.
@vercel

vercel Bot commented Aug 9, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
kitbash Building Building Preview Aug 9, 2026 8:15pm

@github-actions github-actions Bot added documentation Docs, spec, RFCs, README, site dependencies Dependency or action version bumps labels Aug 9, 2026
@singhharsh1708
singhharsh1708 merged commit b751fc1 into main Aug 9, 2026
10 checks passed
@singhharsh1708
singhharsh1708 deleted the feat/mcp-policy branch August 9, 2026 20:16

This branch was successfully deployed

1 active deployment
Preview — eae650e9 Deployed Aug 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency or action version bumps documentation Docs, spec, RFCs, README, site

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant