Repository navigation
Conversation
Every access rule is decided from the caller's identity, and every MCP tool hard-coded `mcp_client`. So every MCP client pointed at one store *was* the same agent, with three consequences, one of them a security hole: - **A cell one MCP client created was readable by all of them.** `created_by` grants access to its creator, and the creator was the same synthetic id for everybody - so the per-cell access model was inert in this binding, which is the cross-agent leakage RFC-AMP-001 §5 lists as a threat. - **`readable_by` naming a real agent id matched nothing.** A caller passing it to `amp_remember` - the documented parameter - stored a cell its own server could not recall. That is the same root cause, and it makes the multi-agent use case the RFC cites for this binding unusable. - **`created_by` recorded a name no agent uses**, which is exactly the attribution §5 leans on to make a poisoned memory traceable. `AMP_MCP_AGENT_ID` now supplies the identity, read per call rather than cached at import, because the MCP client sets the environment when it spawns the process. Unset, it falls back to the old name so nothing breaks - and the fallback is documented as what it is: a shared namespace, not an identity. Both places a user copies from now set it: the getting-started MCP snippet and `examples/mcp-claude-desktop/mcp_config.json`. The release notes gained the caveat next to the other honest limits. Four tests, all of which fail on the old code: the configured id is what lands in `created_by`, the default is used when nothing is configured, a cell restricted to an agent is recallable when the server *is* that agent and invisible when it is another, and `amp_forget` is gated on the same identity.
Owner
Author
|
Landed on master in the v0.1.0 chain: the branch was fast-forward merged as part of |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
fix(mcp): let the MCP binding act as a real agent
Every access rule is decided from the caller's identity, and every MCP tool
hard-coded
mcp_client. So every MCP client pointed at one store was the sameagent, with three consequences, one of them a security hole:
created_bygrants access to its creator, and the creator was the same synthetic id for
everybody - so the per-cell access model was inert in this binding, which is the
cross-agent leakage RFC-AMP-001 §5 lists as a threat.
readable_bynaming a real agent id matched nothing. A caller passing it toamp_remember- the documented parameter - stored a cell its own server couldnot recall. That is the same root cause, and it makes the multi-agent use case
the RFC cites for this binding unusable.
created_byrecorded a name no agent uses, which is exactly the attribution§5 leans on to make a poisoned memory traceable.
AMP_MCP_AGENT_IDnow supplies the identity, read per call rather than cached atimport, because the MCP client sets the environment when it spawns the process.
Unset, it falls back to the old name so nothing breaks - and the fallback is
documented as what it is: a shared namespace, not an identity.
Both places a user copies from now set it: the getting-started MCP snippet and
examples/mcp-claude-desktop/mcp_config.json. The release notes gained thecaveat next to the other honest limits.
Four tests, all of which fail on the old code: the configured id is what lands in
created_by, the default is used when nothing is configured, a cell restricted toan agent is recallable when the server is that agent and invisible when it is
another, and
amp_forgetis gated on the same identity.