TODO Next: MCP without the schema tax (phi meta-tools)
- mcpExpose=phi|direct|auto on RawConfig + MCPConfig; phi default keeps direct as a measured option for small servers (2-tool cheaper direct) - src/mcp.ts: buildMcpMetaTools + phi branch in connectMcp: lazy list/inspect/call behind 3 fixed schemas instead of N per-tool schemas; direct branch kept; bindMcpGuard wires permission+PluginHost guard for MCP calls through the same gate as built-ins - prompt mcpServers names-only under phi; under direct schemas travel as before — 20-tool server ~2750 tok -> ~phi (names) until mcp_call - session: isDirect mcpServerNames non-enumerable marker, activeTools hides mcp_call from pre-wired rules when inside mcp_call, /tools shows mcp_call and Enabled/Withheld reflects the 3 meta-names under phi - permission: mcp_* as read (free), mcp_call mutating keyed by server.tool, same top-level suppression + ask-to-approve as other mutating tools - cli: bindMcpGuard + /mcp list shows exposure + mcp_* listed; headless denies line mentions mcp_list - commit.ts: git_commit_message kept in git set via toolSetOf/ disabledToolNames overlay Tests: 798 pass, 0 fail; tsc exit 0; mcp.test.ts covers phi stays empty until mcp_call and direct still namespaced.
This commit is contained in:
@@ -40,11 +40,11 @@ Every MCP tool's schema goes into the prompt today, so twenty tools from one ser
|
||||
phi solves this with three meta-tools — `mcp_list`, `mcp_inspect`, `mcp_call` — and a prompt that
|
||||
names only the servers. A hundred servers then cost almost nothing until one is called.
|
||||
|
||||
- [ ] `mcp_list` / `mcp_inspect` / `mcp_call` replacing per-tool registration
|
||||
- [ ] The prompt lists server names, not schemas
|
||||
- [ ] Calls go through the same permission rules and guard as a built-in
|
||||
- [ ] Keep per-tool registration as an option: a two-tool server is cheaper registered directly
|
||||
- [ ] Test: a configured server contributes no schema to the request until `mcp_call`
|
||||
- [x] `mcp_list` / `mcp_inspect` / `mcp_call` replacing per-tool registration (`src/mcp.ts`: phi meta-tools, lazy list/inspect/call, `mcpExpose=phi`)
|
||||
- [x] The prompt lists server names, not schemas (`src/prompt.ts`: `mcpServers` names-only, direct schemas omitted under phi)
|
||||
- [x] Calls go through the same permission rules and guard as a built-in (`permission mcp_call` + `bindMcpGuard`, intra-turn suppressed, ask-to-approve otherwise)
|
||||
- [x] Keep per-tool registration as an option: a two-tool server is cheaper registered directly (`mcpExpose=direct` / `mcpExpose=auto`)
|
||||
- [x] Test: a configured server contributes no schema to the request until `mcp_call` (`test/mcp.test.ts` phi vs direct)
|
||||
|
||||
### Derive the tool-name lists
|
||||
|
||||
|
||||
Reference in New Issue
Block a user