88369af1c7
Policy applied (per Teknium direction, matching the Cloudflare precedent): raw tool surfaces only — no server-side code-mode/search-execute layers, no vendor tool_search; bloat (telemetry, feedback, docs-lookup, static-guidance pseudo-tools, plan-gated upsells, dupe batch/compat shims) pruned via manifest defaults. DROPPED (meta-tool gateway IS the server, no vendor off-switch): zapier (discover/enable/execute over 40k actions), wix (CallWixSiteAPI generic invoke), customer-io (cio_read/write/delete_api generic HTTP executors), omnisend (4 generic verb executors), apify (dynamic actor-mount + telemetry-on-by-default), ramp (undocumented SQL/ETL layer, no tool list, money-moving approval tools) URL-LEVEL DEBLOAT (vendor-documented switches): postman -> /minimal variant; klaviyo -> ?core-tools-only=true& disable-tools-with-user-generated-content=true (262 -> ~40 tools) CURATED default_excluded (20 entries) / default_enabled (kiwi, motherduck): monday (GraphQL escape hatch trio...), close (voice-agent cluster that places real AI phone calls, search/fetch layer, 14 excl), betterstack (Execute query SQL hatch, 8 instruction pseudo-tools, team mgmt, 14 excl), mixpanel (6 guidance pseudo-tools, bulk dupes, 10 excl), neon (search/ fetch, docs pair, logs beta, auth product, 10 excl), miro (6 deprecated), gamma (viewer-tracking analytics), robinhood (upsell+social), dropbox, todoist, fireflies, calendly, plaid, attio, gitlab, circleci, buildkite (secrets-exposing get_job_env), semgrep, globalping, prisma-postgres, motherduck (9-tool core enable), kiwi (feedback tool pruned) Clean after audit (no changes needed): canva, clickup, linear-class lean servers, twelve-data (read-only), algolia (read-only, vendor-curated), indeed, strava (vendor read-only, no tool list published), craft, wordpress-com (user-side toggles documented), trivago, alltrails, deepwiki, context7, microsoft-learn, aws-knowledge, wolfram, twilio-docs
41 lines
1.2 KiB
YAML
41 lines
1.2 KiB
YAML
# Nous-approved MCP catalog entry.
|
|
# Presence in this directory = approval. Merged via PR review.
|
|
manifest_version: 1
|
|
|
|
name: calendly
|
|
description: Scheduling links, events, and invitees from Calendly.
|
|
source: https://developer.calendly.com/calendly-mcp-server
|
|
|
|
# Official vendor-hosted remote MCP (URL-only — Hermes never spawns a local
|
|
# process for this entry). Native OAuth 2.1 + Dynamic Client Registration
|
|
# (verified live: RFC 9728 protected-resource metadata -> AS metadata with
|
|
# registration_endpoint); Hermes's MCP client + mcp_oauth_manager handle
|
|
# discovery, PKCE, token exchange, and refresh.
|
|
|
|
transport:
|
|
type: http
|
|
url: https://mcp.calendly.com
|
|
|
|
auth:
|
|
type: oauth
|
|
|
|
# Excluded: vendor skill-discovery pair (instruction-loading indirection —
|
|
# Hermes skills/tool_search cover this).
|
|
tools:
|
|
default_excluded:
|
|
- list_calendly_skills
|
|
- load_calendly_skill
|
|
|
|
# Composer-suggestion triggers (desktop brand pills).
|
|
suggest:
|
|
keywords:
|
|
- calendly
|
|
- scheduling
|
|
hosts:
|
|
- calendly.com
|
|
|
|
post_install: |
|
|
On first connection Hermes opens a browser to authorize with
|
|
Calendly (or run `hermes mcp login calendly`). Approve access,
|
|
then restart the session so tools load.
|