fix(mcp): preserve investigation input policy#400
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
REA_INVESTIGATION_INPUT_ROOTS_JSONin managed MCP client registrationsRoot cause
The static JavaScript tool correctly failed closed when no investigation roots were configured, but
rea setupomitted that non-secret policy from managed MCP registrations. The live capability inventory also grouped static analysis with Electron observation, and permission denials incorrectly advertised no restart even though a running MCP process cannot acquire a changed environment through elicitation or SIGHUP.Impact
Operators can set the explicit investigation root before approved setup and have it retained in the registered MCP environment. Agents see the tool as policy-disabled before attempting it when the ceiling is empty, and receive accurate administrator-reconfiguration and restart instructions.
The security boundary remains fail-closed: elicitation can add a connection grant only within the configured administrator ceiling and cannot widen it.
Validation
npm run checknpm run verify:packagewith a Linux-only PATH (the inherited WSL PATH contains nonresponsive Windows npm/npx shims that exceed the verifier setup prompt deadline)npm run knipnpm run jscpdnpm run scan:todosReal Hopper and Ghidra verification was not run because no provider protocol or analysis behavior changed.