From d6a6d87c4a90ed61fd65ee6c083f0aa985a0e302 Mon Sep 17 00:00:00 2001 From: nftpoetrist <264138787+nftpoetrist@users.noreply.github.com> Date: Sun, 30 Aug 2026 02:00:52 +0300 Subject: [PATCH] fix(tools): restore setup_mcp's never-hand-edit instruction MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 9d9f44d638 removed the desktop platform hint's "never hand-edit mcp_servers config for them" sentence, reasoning it was a "word-for-word duplicate of the setup_mcp tool schema... taught on every call." The schema has never contained that instruction — only "never re-ask after a decline." setup_mcp is desktop_ui-toolset-only and no runtime guard in agent/file_safety.py covers mcp_servers config, so removing the only place teaching this left a real gap: a model asked to add/configure an MCP server could just write_file into mcp_servers config directly, bypassing the consent-card/OAuth flow the tool exists to enforce. Restored the instruction directly in SETUP_MCP_SCHEMA's description — completing the original commit's stated intent (move it to the schema) rather than reverting to the platform hint, since the schema reaches every setup_mcp call regardless of platform hint wording changes. Added a regression test asserting the schema description forbids hand-editing mcp_servers config, so a future prompt-diet pass can't silently drop it again without a test failing. --- tests/tools/test_setup_mcp_tool.py | 10 +++++++++- tools/setup_mcp_tool.py | 3 ++- 2 files changed, 11 insertions(+), 2 deletions(-) diff --git a/tests/tools/test_setup_mcp_tool.py b/tests/tools/test_setup_mcp_tool.py index ae7be1d418..12842b6a71 100644 --- a/tests/tools/test_setup_mcp_tool.py +++ b/tests/tools/test_setup_mcp_tool.py @@ -11,7 +11,15 @@ import json import pytest -from tools.setup_mcp_tool import setup_mcp_tool +from tools.setup_mcp_tool import SETUP_MCP_SCHEMA, setup_mcp_tool + + +def test_schema_forbids_hand_editing_mcp_servers_config(): + # Nothing else teaches the model this: the tool is desktop_ui-only, so + # without it a model could just write_file into mcp_servers config + # directly, bypassing the consent-card/OAuth flow this tool exists for. + assert "hand-edit" in SETUP_MCP_SCHEMA["description"] + assert "mcp_servers" in SETUP_MCP_SCHEMA["description"] def test_requires_desktop_callback(): diff --git a/tools/setup_mcp_tool.py b/tools/setup_mcp_tool.py index 41f081735c..624540016b 100644 --- a/tools/setup_mcp_tool.py +++ b/tools/setup_mcp_tool.py @@ -77,7 +77,8 @@ SETUP_MCP_SCHEMA = { "Propose an MCP server as an inline consent card (install a catalog " "entry, re-enable a disabled server, or run OAuth); blocks until the " "user acts. Use when they ask to add an MCP or a task clearly needs " - "a missing one. Never re-ask after a decline — on declined/" + "a missing one. Never hand-edit mcp_servers config for them — always " + "use this tool. Never re-ask after a decline — on declined/" "unanswered, continue without it. Catalog names: `hermes mcp " "catalog` in the terminal." ),