Files
hermes-agent/optional-mcps/railway/manifest.yaml
T
Teknium 054cba271e fix(mcp): review findings — reinstall no longer clobbers user exclude lists + 4 curation gaps
Review blockers (independent reviewer on #94513):
1. Reinstalling an exclude-mode catalog entry wiped the user's edited
   tools.exclude, replacing it with manifest defaults. install_entry now
   reads the prior exclude (like it already did for include) and re-writes
   it verbatim on reinstall. Regression test added + sabotage-verified
   (fails on old behavior); include-priority test added too.
2. aws-knowledge: exclude aws___retrieve_skill — vendor SKILL.md loader is
   a vendor skill layer (live tools/list confirmed the tool exists).
3. betterstack: exclude list rewritten to cover the snake_case wire names
   (vendor's own header examples show remove_dashboard) via globs alongside
   the doc display-labels; caveat documented in the manifest — server is
   OAuth-gated so pre-auth enumeration is impossible.
4. railway: exclude railway-agent (opaque server-side agent delegation,
   acts outside Hermes's per-tool approval loop).
5. twelve-data: exclude oauth plumbing pseudo-tools + quota probe.
6. betterstack post_install no longer claims a fully-checked checklist —
   exclude-mode bypasses the checklist; text now describes the applied
   exclude list.

Live E2E: fresh temp HERMES_HOME — install applies manifest excludes,
user edit survives reinstall. 33/33 catalog tests green.
2026-08-25 04:21:37 -07:00

42 lines
1.3 KiB
YAML

# Nous-approved MCP catalog entry.
# Presence in this directory = approval. Merged via PR review.
manifest_version: 1
name: railway
description: 'Railway: projects, services, deployments, and environments.'
source: https://docs.railway.com/guides/mcp-server
# Official vendor-hosted remote MCP (URL-only — Hermes never spawns a local
# process for this entry). Native OAuth 2.1 + Dynamic Client Registration
# (verified live: RFC 9728 protected-resource metadata -> AS metadata with
# registration_endpoint); Hermes's MCP client + mcp_oauth_manager handle
# discovery, PKCE, token exchange, and refresh.
transport:
type: http
url: https://mcp.railway.com
auth:
type: oauth
# Excluded: railway-agent hands the request to Railway's server-side AI
# agent for multi-step infra operations — an opaque delegation meta-layer
# that acts outside Hermes's per-tool approval loop. The remaining tools
# are direct (and destructive ones carry vendor destructive-hints).
tools:
default_excluded:
- railway-agent
# Composer-suggestion triggers (desktop brand pills).
suggest:
keywords:
- railway
- railway deploy
hosts:
- railway.com
- railway.app
post_install: |
On first connection Hermes opens a browser to authorize with
Railway (or run `hermes mcp login railway`). Approve access,
then restart the session so tools load.