github / github/github-mcp-server

Inventory: return stable hidden-tool reason codes across filter gates

Đang mở
#2,197 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
Go
Star
33k
Fork
5k
Merge trung bình
2 ngày 1 giờ
Pull request đã merge (30 ngày)
52

Mô tả

## Problem
Tool filtering can hide capabilities due to toolset, PAT scope, read-only mode, or lockdown, but callers do not always receive one stable reason classification.

## Why now
Permission-scoped capability exposure is a core contract of the GitHub MCP server. Missing provenance for hidden tools weakens operator debugging and policy auditability.

## Current insufficiency
Filtering behavior is implemented in multiple layers, but there is not a single stable reason-code contract guaranteed across all hide paths.

## Expected behavior
Hidden tools should be classified with deterministic reason codes such as:
- `toolset_filtered`
- `scope_filtered`
- `readonly_filtered`
- `lockdown_filtered`

## Validation requirements
- Add tests that exercise each hide path.
- Assert one stable reason code per hidden tool decision.
- Keep classification convergent across inventory and request filtering.

## Scope map
- `internal/ghmcp/server.go`
- `pkg/inventory/builder.go`
- `pkg/scopes/fetcher.go`
- `pkg/lockdown/lockdown.go`

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.