Repository navigation
feat(mcp): tell agents which upstream servers they can reach - #1486
Merged
github-actions[bot] merged 1 commit intoOct 3, 2026
Merged
Conversation
Agents connected through mcpproxy did not realise upstream tools sit behind retrieve_tools and fell back to shell CLIs (gh, curl, ...). - Fix: /mcp, /mcp/call, /mcp/code and /mcp/p/<slug> are served by callToolServer/codeExecServer, which carried no initialize instructions at all (only p.server did). They now share the default. - Per-caller instructions (initialize and server/discover): the default is recomposed from the built-ins the caller actually sees, plus a YOUR ACCESS block listing the active profile (never the anonymous_profile), reachable servers (enabled, approved, connected, in profile and token scope) and allowed operation tiers (token permissions with the profile max_tier, noting tools.allow exemptions). - retrieve_tools description gains a reach note and a per-caller "CONNECTED SERVERS searchable here" suffix, so client-side tool search (Claude Code) matches service names; tools/list_changed is sent when the reachable set changes. Only names matching a conservative charset are spelled out (prompt-injection guard). - advertise_upstream_servers (default true, hot-reloadable) opts out of naming servers. - mcpproxy agent-instructions prints a CLAUDE.md/AGENTS.md snippet that follows routing_mode, optionally with the connected servers. - Docs: features/agent-instructions, config reference, links from connect-clients, routing-modes and quick-start. Spec 105 SC-005 now pins operator instructions as identical for every caller; the generated access block is per caller and scope-filtered.
Deploying mcpproxy-docs with
|
| Latest commit: |
0c38dac
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://c614eb29.mcpproxy-docs.pages.dev |
| Branch Preview URL: | https://claude-mcp-proxy-server-visi.mcpproxy-docs.pages.dev |
|
Codecov Report❌ Patch coverage is 📢 Thoughts on this report? Let us know! |
3 tasks done
github-actions Bot
pushed a commit
that referenced
this pull request
Oct 3, 2026
…1487) ## Description Fixes three LOW findings from the zcode (GLM-5.3) review of #1486: - **Config load failure (`cmd/mcpproxy/agent_instructions_cmd.go`):** `mcpproxy agent-instructions` used to discard a config load error and print the default retrieve_tools workflow with exit 0. It now warns on stderr, the same way `--with-servers` already does. - **`upstream_servers` line:** the default snippet always said to use `upstream_servers`. With `disable_management` or `read_only_mode` that tool is absent (`internal/server/mcp.go` management guard), so the line is now omitted in that case. - **Godoc (`internal/profile/policy.go`):** `HasAllowRules` had been inserted inside `Decide`'s doc comment, so `Decide` lost its godoc. The method now sits below `Decide`. No behaviour change. Not needed for v0.70.0-rc.3. ## Testing - [x] I have tested these changes locally - [x] I have added/updated tests that prove my fix is effective or my feature works - [x] All existing tests pass New test: `TestBuildAgentInstructions_OmitsUpstreamServersWithoutManagement`. `go test ./cmd/mcpproxy/ -run AgentInstructions` and `./internal/profile/` pass. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pull Request
Description
Users report that Claude Code and Codex connected through mcpproxy "don't see" upstream servers. The agents then fall back to
gh,curland similar instead of the proxied tools. This PR fixes the cause and tells each agent what it can reach.Bug:
/mcpsent no initialize instructions./mcp,/mcp/call,/mcp/codeand/mcp/p/<slug>are served bycallToolServerandcodeExecServer, not byp.server. Onlyp.serveranddirectServerhadWithInstructions, so a default client never learned that upstream tools sit behindretrieve_tools. Both servers now carry the instructions (mcp_routing.go).Per-caller guidance (
internal/server/mcp_agent_access.go)server/discoverinstructions: the default text is rebuilt from the built-in tools this caller actually sees. Its new clauses say upstream tools aren't listed individually, and that the agent should searchretrieve_toolsbefore using a shell CLI or raw API. A YOUR ACCESS block lists:anonymous_profile;max_tier, notingtools.allowexemptions;retrieve_toolsdescription: gains a "reachable ONLY through this tool" note and a per-callerCONNECTED SERVERS searchable here: …suffix. Claude Code's tool search can then match "github" toretrieve_tools.tools/list_changedonly when the reachable server set, or the advertise flag, changes.^[A-Za-z0-9][A-Za-z0-9._-]{0,63}$. Other names count toward "+N more", as a prompt-injection guard.advertise_upstream_servers, defaulttrueand hot-reloadable.serverInScope,ScopedViewwith anonymous confinement, the token's permissions, andCompiledPolicy.Decide.CLI and docs
mcpproxy agent-instructions [--with-servers] [--client cursor]prints a CLAUDE.md / AGENTS.md snippet that follows the configuredrouting_mode.docs/features/agent-instructions.md, linked from the connect-clients, routing-modes and quick-start pages and from the config reference.What a reviewer should know
retrieve_toolsdescription changed, so fourtoolslist_goldensfiles were regenerated.retrieve_toolswas added totoolsListAllowedDelta, and the pre-105 comparison allows exactlyretrieveToolsReachNote.noResolutionRecordKey). Recording a session resolution at initialize changed which sessions a later profile edit notifies.set_profilesends notools/list_changed(known limitation): sending it mid-call turns the streamable-HTTP JSON response into an event stream, which breaks JSON-only clients. The stale text only names servers this same session could already reach. This is documented.Testing
I have tested these changes locally
I have added/updated tests that prove my fix is effective or my feature works
All existing tests pass
New tests:
Live check, isolated instance: an admin saw both servers; a read-only token scoped to one server saw only that server, plus the refused tiers, in both initialize and
tools/list.Suites and builds: the race suite with
-tags serverpasses for server, profile, config, runtime, storage, httpapi and cmd. Lint is clean, and the strict docs build passes.Cross-model review: zcode produced no verdict. opencode (Sol) found 8 issues over four rounds; all were fixed except the
set_profilelimitation above, and the final round came back clean.🤖 Generated with Claude Code