mirror of
https://github.com/openswarm-ai/openswarm.git
synced 2026-09-28 12:34:50 +02:00
fix(mcp): wildcard allowlist when _tool_descriptions is unset
The agent_manager composer iterated tool_permissions._tool_descriptions
to build the per-tool allowlist passed to the claude CLI. When that map
was empty (an MCP tool added without populating it), zero tool names
were allowlisted, so the CLI rejected every sub-tool the server actually
advertised with "No such tool available". Mirror the unknown-tool
fallback: emit mcp__{name}__* and still honor explicit denies.
This commit is contained in:
@@ -1826,10 +1826,18 @@ class AgentManager:
|
||||
if tool_def:
|
||||
denied = _get_denied_tool_names(tool_def)
|
||||
known = _get_all_known_tool_names(tool_def)
|
||||
for tn in known - denied:
|
||||
policy = tool_def.tool_permissions.get(tn, "ask")
|
||||
if policy == "always_allow":
|
||||
effective_allowed.append(f"mcp__{name}__{tn}")
|
||||
if known:
|
||||
for tn in known - denied:
|
||||
policy = tool_def.tool_permissions.get(tn, "ask")
|
||||
if policy == "always_allow":
|
||||
effective_allowed.append(f"mcp__{name}__{tn}")
|
||||
else:
|
||||
# _tool_descriptions never populated (discovery skipped or
|
||||
# the server's schema was unavailable). Trust the server
|
||||
# via wildcard so freshly added MCP tools are not silently
|
||||
# filtered out of the CLI allowlist; explicit denies below
|
||||
# still apply.
|
||||
effective_allowed.append(f"mcp__{name}__*")
|
||||
for tn in denied:
|
||||
effective_disallowed.append(f"mcp__{name}__{tn}")
|
||||
else:
|
||||
|
||||
Reference in New Issue
Block a user