Let a bot file an MCP server switched off - #2212
Conversation
The user can ask a bot to add an MCP connection. It is saved disabled, the bot cannot enable or test it, and an existing server is left unchanged.
|
@guylfe is attempting to deploy a commit to the SupaMaus Team on Vercel. A member of the Team first needs to authorize it. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (9)
Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 2 remain after this review. 📝 WalkthroughWalkthroughThe change adds an internal endpoint for bot-submitted MCP server configurations. It validates and stores new servers as disabled, then exposes an agent tool that submits configurations and reports the result. ChangesMCP server submission
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant Agent
participant callTool
participant InternalMcpEndpoint
participant MCPRegistry
participant MCPConfiguration
Agent->>callTool: invoke add_mcp_server
callTool->>InternalMcpEndpoint: POST server arguments
InternalMcpEndpoint->>MCPRegistry: validate and add disabled server
MCPRegistry-->>InternalMcpEndpoint: server and updated configuration
InternalMcpEndpoint->>MCPConfiguration: persist updated configuration
InternalMcpEndpoint-->>callTool: server details or error
callTool-->>Agent: tool result
Suggested reviewers: Merge Risk: ⚪ Minimal · up to The change lets a bot file an MCP server switched off, with checks that block enabling, overwriting, or exposing secrets. No actionable merge-blocking risk is evident. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to Connections stay disabled, but the new submission path does not verify that the user authorized each addition. This could allow unwanted entries in shared connection settings. Separate activation, duplicate rejection, and credential-value filtering substantially limit immediate impact. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 3 | ❌ 1 | ❓ 1❌ Failed checks (1 warning, 1 inconclusive)
✅ Passed checks (3 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 40.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 7 files. (5 skipped: 3 unsupported, 2 too large.)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
… cloud-move test (#2263) * test: route ratchet counts the internal MCP route from #2212 #2212 added POST /api/internal/mcp-servers to server/index.ts. Its CI ran before the ratchet (#2241) merged, so main now fails the ratchet (165 > 164) and every open PR fails with it. Internal harness routes have no server/routes module yet, so the honest count is 165 until they move out. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test(electron): cloud-move reads main.mjs with LF line endings The Copy-to-server test sliced a function out of main.mjs by searching for "\n}\n", which a Windows checkout (CRLF) never contains, so the test failed on every Windows run since #2246. Normalize like the other main.mjs readers. Checked by converting main.mjs to CRLF locally: the old test fails 1/33, the new one passes 33/33. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
The user can ask a bot to add an MCP connection. It is saved disabled, the bot cannot enable or test it, and an existing server is left unchanged.
Summary by CodeRabbit