fix(mcp): align answer and Asset behavior - #368
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (4)
📒 Files selected for processing (11)
📜 Recent review details🧰 Additional context used📓 Path-based instructions (2)**/*📄 CodeRabbit inference engine (AGENTS.md)
Files:
**/*.{yml,yaml,properties}📄 CodeRabbit inference engine (AGENTS.md)
Files:
🧠 Learnings (4)📚 Learning: 2026-07-26T05:46:47.443ZApplied to files:
📚 Learning: 2026-07-26T05:46:49.308ZApplied to files:
📚 Learning: 2026-07-29T10:41:24.263ZApplied to files:
📚 Learning: 2026-08-05T09:53:56.596ZApplied to files:
🪛 ast-grep (0.45.1)apps/mcp/src/test/java/com/orgmemory/mcp/AssetDeliveryToolsTests.java[warning] 111-114: Avoid LDAP injections (ldap-injection-java) apps/mcp/src/main/java/com/orgmemory/mcp/AssetDeliveryTools.java[warning] 58-59: Avoid LDAP injections (ldap-injection-java) 🪛 markdownlint-cli2 (0.23.2).tegami/mcp-answer-and-asset-behavior.md[warning] 7-7: First line in a file should be a top-level heading (MD041, first-line-heading, first-line-h1) 🔇 Additional comments (34)
📝 WalkthroughWalkthroughMCP knowledge searches now return stable source numbers. Asset searches enforce bounded limits. Tool descriptions, server instructions, and rendered prompts define authorization, policy precedence, citation, disclosure, and access-gap behavior. ChangesMCP behavior
Estimated code review effort: 3 (Moderate) | ~25 minutes Merge Risk: ⚪ Minimal · up to The PR updates MCP answer and Asset behavior with bounded search results and explicit execution guidance; no actionable merge-blocking risk remains beyond normal checks and review. Possibly related PRs
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai review |
✅ Action performedReview finished.
|
TegamiThis repository uses Tegami to manage releases. When your changes affect published packages, add a changelog file under Create a changelog → · Changelog format Release preview
Changelogs in this PR
Run Managed by Tegami. |
Scope
search_knowledgeallowedToolsas compatibility metadata rather than a permission grantaccessGapbehavior and require explicit user intent before Asset execution or installationsearch_assetsto 10 candidates by default and 20 maximumreleased_promptas a user-role task messageEvidence
./gradlew.bat --no-daemon compileJava :apps:mcp:test./gradlew.bat --no-daemon clean testAssetDeliveryToolsTestsandOrgMemoryMcpContextTestspy -3 scripts/check_docs.pycorepack pnpm release:checkgit diff --checkUI approval
Not applicable. This PR changes MCP contracts, metadata, and server behavior only; it has no web or authentication UI paths.
Release and risk
.tegami/mcp-answer-and-asset-behavior.mdSummary by CodeRabbit
New Features
Bug Fixes