From 499eb16badbf82770273d216bad2cec5a1c8c29b Mon Sep 17 00:00:00 2001 From: TheAchiever6823 <61914223+ShawnMadadha@users.noreply.github.com> Date: Fri, 15 May 2026 22:15:20 -0700 Subject: [PATCH] fix(mcp): wildcard allowlist when _tool_descriptions is unset The agent_manager composer iterated tool_permissions._tool_descriptions to build the per-tool allowlist passed to the claude CLI. When that map was empty (an MCP tool added without populating it), zero tool names were allowlisted, so the CLI rejected every sub-tool the server actually advertised with "No such tool available". Mirror the unknown-tool fallback: emit mcp__{name}__* and still honor explicit denies. --- backend/apps/agents/agent_manager.py | 16 ++++++++++++---- 1 file changed, 12 insertions(+), 4 deletions(-) diff --git a/backend/apps/agents/agent_manager.py b/backend/apps/agents/agent_manager.py index ffc355bb..fde3380b 100644 --- a/backend/apps/agents/agent_manager.py +++ b/backend/apps/agents/agent_manager.py @@ -1826,10 +1826,18 @@ class AgentManager: if tool_def: denied = _get_denied_tool_names(tool_def) known = _get_all_known_tool_names(tool_def) - for tn in known - denied: - policy = tool_def.tool_permissions.get(tn, "ask") - if policy == "always_allow": - effective_allowed.append(f"mcp__{name}__{tn}") + if known: + for tn in known - denied: + policy = tool_def.tool_permissions.get(tn, "ask") + if policy == "always_allow": + effective_allowed.append(f"mcp__{name}__{tn}") + else: + # _tool_descriptions never populated (discovery skipped or + # the server's schema was unavailable). Trust the server + # via wildcard so freshly added MCP tools are not silently + # filtered out of the CLI allowlist; explicit denies below + # still apply. + effective_allowed.append(f"mcp__{name}__*") for tn in denied: effective_disallowed.append(f"mcp__{name}__{tn}") else: