Skip to content

v1.1.0

Choose a tag to compare

@github-actions github-actions released this 20 Sep 17:07

MCP Dev Runtime v1.1.0

Optional local Skill discovery and reading, with unchanged six-tool defaults and no additional agent/model calls. This is a regular release; the two new Skill tools are explicitly experimental and disabled by default.

Downloads / 下载

Archive Native acceptance baseline
mcp-dev-runtime-1.1.0-darwin-arm64.tar.gz Apple Silicon, macOS 14
mcp-dev-runtime-1.1.0-darwin-x64.tar.gz Intel Mac, macOS 15
mcp-dev-runtime-1.1.0-linux-x64-gnu.tar.gz Ubuntu 22.04 x64, glibc + GCC 12 libstdc++
mcp-dev-runtime-1.1.0-linux-arm64-gnu.tar.gz Ubuntu 22.04 ARM64, glibc + GCC 12 libstdc++

Each archive includes Node.js 24.21.0, compiled MDR, production native dependencies, the pinned YAML parser 2.9.1, and tunnel-client-runtime from 70bb5a7e1305596f0216d7b18d0b7765d58576d5. No system Node/npm/Go/compiler is needed to install or run MDR. Development tools required by your projects remain your responsibility.

SHA256SUMS covers the four final archives. VERIFICATION.json contains per-platform acceptance records. Each archive includes a file-hash manifest, component licenses and SPDX inventory; GitHub build provenance is generated separately.

Publisher code signing and Apple notarization remain deliberately skipped. The existing signing integration boundary is preserved. The installer does not disable or bypass operating-system protections.

What's new

  • Add two read-only, opt-in experimental MCP tools: discover_skills finds relevant metadata, and read_skill reads complete SKILL.md instructions and selected UTF-8 reference files. Neither tool executes scripts, installs dependencies, starts another agent or calls a model API.
  • Discover user roots ~/.agents/skills, $CODEX_HOME/skills (normally ~/.codex/skills) and existing .system skills. Discover project .agents/skills and compatibility .codex/skills roots within the current Git/worktree boundary. Explicit additional roots and disabled paths are supported.
  • Add bounded metadata search using weighted BM25/Han matching, canonical-path deduplication, explicit same-name disambiguation, lazy shared caches and scoped/versioned continuation cursors. Resource traversal, escaping links, special files, invalid text and over-budget reads fail explicitly.
  • Respect implicit-invocation policy from agents/openai.yaml; malformed policy is conservative. Skill dependencies are informational, never automatic authorization or installation instructions.
  • Add short task-level MCP guidance only when the Skill tools are enabled. New substantive tasks should discover once; explicitly named skills may be read directly; selected instructions must be read completely. Simple checks, output polling and unchanged-task continuations avoid repeated discovery.
  • Ship service-style start, stop, safe restart, and the --bg shorthand. Existing up, down and --background remain supported.
  • Add bilingual Skill guidance, lazy-loading/scope/resource-safety tests, HTTP/stdio and extracted-package checks, plus an interleaved Skill benchmark.

Compatibility and opt-in behavior

The original six tools retain their names and input/output schemas. Their default instructions are unchanged when Skills are disabled. The existing stable tool contract remains 3.1; two additional experimental tool definitions are advertised only when explicitly included in tools.allow.

Existing unified and legacy split configuration remains supported. Installation and upgrade preserve configuration: they do not enable Skills, move existing data, change Tunnel IDs or restart the user's active deployment automatically. Review active tasks and stop the selected managed service before upgrading.

To enable Skills after upgrading, merge the two additional names into the existing allowlist; do not replace unrelated settings:

{
  "tools": {
    "allow": [
      "exec_command",
      "write_stdin",
      "apply_patch",
      "view_image",
      "list_exec_sessions",
      "terminate_exec_session",
      "discover_skills",
      "read_skill"
    ]
  }
}

No separate skills configuration is needed for default roots. Optional skills.extra_roots and skills.disabled_paths can be configured in the same JSON file. Inspect the effective policy with mdr tools and non-secret settings with mdr config.

After a deliberate restart, refresh tools in the MCP client and test in a new conversation. No native ChatGPT Skill-upload interface is required. Skill file changes are picked up by an explicit refresh or the next request after cache expiry; no permanent filesystem watcher or periodic background scanner is added.

Installation and uninstall

Verify the full archive hash against SHA256SUMS, extract the archive for your platform, and run ./install.sh without sudo. The runtime package includes its own Node and pinned Tunnel. ./uninstall.sh requires interactive y confirmation for complete MDR-owned removal; shared user Skill roots are not owned or deleted by MDR.

English installation · 中文安装 · Local Skills · 本机 Skill

Verification scope and limitations

Every published platform archive must pass the full source regression, CLI/static checks and native extracted-package verification. Package acceptance includes the existing 20 real-tool checks, isolated opt-in Skill discovery/reading/pagination using bundled dependencies, and install/upgrade/rollback/uninstall behavior. VERIFICATION.json is the record for the final published artifacts.

Hosted-client automatic Skill selection is not certified by SDK tests: prompting, refresh behavior, actual trigger/selection accuracy, model-context costs and Tunnel WAN latency require separate ChatGPT acceptance. Benchmarks are local measurements, not an identical-to-Codex success-rate or latency guarantee. The service does not intercept user messages or force Skill discovery before ordinary tool execution.

Skill text reaches the connected client/model. Skill policies and the tool allowlist do not replace an OS sandbox or expand user authorization. Windows, Alpine/musl, automatic boot services and multi-user isolation remain outside this release. CI uses explicit mock/isolated Tunnel lifecycle tests, not private credentials or real cloud round trips on every platform.

中文摘要

v1.1.0 新增需要主动启用的 discover_skills、read_skill,支持全局与项目目录发现、相关候选搜索、完整指令和引用文件读取,以及有界缓存与 UTF-8 分页。默认仍只有原来的六个工具,原 schema 不变;不调用 Codex、其他 Agent 或模型,也不自动安装或执行 Skill 中的脚本。

本版同时包含 start、stop、安全 restart 和 --bg;旧命令继续兼容。新旧配置均保留,升级不会自动开启 Skill 或重启现有实例。需要启用时,把两个工具名加入已有 tools.allow,检查活动任务后主动重启,再刷新 ChatGPT 工具。

四个平台分别原生构建并验收,附校验文件和验证记录;签名和 Apple 公证仍跳过。网页版模型是否自然地主动选择 Skill,需要单独验证,不能由本地 SDK 或安装包测试代替。