3 Commits

Author SHA1 Message Date
Teknium 3a1a3a1c8f feat(mcp): curated exclude list for cloudflare + glob tool filters + default_excluded manifests
The cloudflare entry's 3,320-endpoint surface is ~43% product families a
personal/dev account never touches (Zero Trust org-fleet suite, Magic
Transit/WAN, Cloudforce One, Radar analytics, API Shield, legacy
migration surfaces). Ship a 34-pattern curated exclude list in the
manifest: 3,320 -> 1,905 tools kept, and everything Cloudflare adds
later stays enabled by default.

Mechanism, two small extensions:
- tools/mcp_tool.py: tools.include/exclude entries containing glob
  metacharacters now match via fnmatch (plain names stay exact-match),
  so a product family is one pattern instead of hundreds of stale
  literals.
- hermes_cli/mcp_catalog.py: manifests may declare
  tools.default_excluded (mutually exclusive with default_enabled);
  install writes it to tools.exclude and skips the probe/checklist —
  a 3,320-row curses checklist is not a UX. Prior user include
  selections still win on reinstall.

Verified by replaying the real filter functions over the live-probed
3,320-tool list: 1,415 excluded, zero overmatch against a per-product
target audit; DNS/Workers/R2/D1/tunnels/Access/AI kept.
2026-08-25 04:21:37 -07:00
Teknium 53015d3eb5 feat(mcp): pin ?codemode=false so tool_search sees the full endpoint surface
The server's default Code Mode surface (search/execute meta-tools) is
itself a tool-discovery layer; stacking it under Hermes tool_search
would mean two search hops and an opaque 2-tool surface. With
?codemode=false each of the ~3,300 API endpoints registers as its own
tool with a full JSON Schema, and Hermes's own progressive disclosure
defers and searches the complete catalog — one layer, total
information. Verified live: tools/list returns 3,320 tools, all with
input schemas. post_install documents the trade-off and how to opt
back into Code Mode.
2026-08-25 04:21:37 -07:00
Teknium 90fd9a838b feat(mcp): add Cloudflare's official API MCP server to the catalog
Adds optional-mcps/cloudflare — Cloudflare's managed remote MCP server
(mcp.cloudflare.com/mcp) fronting the entire Cloudflare API (2,500+
endpoints across DNS, Workers, R2, KV, D1, Zero Trust, WAF, Pages)
through two Code Mode tools, search() and execute(), at a fixed ~1k-token
schema footprint. HTTP transport + native MCP OAuth 2.1 with DCR — no
install block, nothing to pin. post_install documents the scoped OAuth
grant, the bearer-token path for headless/CI, and Cloudflare's
product-specific servers for narrower surfaces.

Docs: mention Cloudflare in the hosted-OAuth MCP examples.
2026-08-25 04:21:37 -07:00