Skip to content

Add MCP client support: connect Kody to user-added remote MCP servers - #662

Merged
kody-bot merged 8 commits into
mainfrom
cursor/remote-mcp-servers-baf1
Jul 8, 2026
Merged

kody-bot merged 8 commits into
mainfrom
cursor/remote-mcp-servers-baf1

Conversation

@kentcdodds

@kentcdodds kentcdodds commented Jul 8, 2026 •

Copy link
Copy Markdown
Owner

Kody can now act as an MCP client: users add remote MCP servers (OAuth-protected or open), and the tools those servers expose become Kody capabilities callable from execute via kody.mcp["server-name"].tool_name(...). Servers are manageable both in the UI (/account/mcp-servers) and through the new mcp_servers capability domain.

Demo

Adding an OAuth-protected MCP server in the UI, authorizing it, and seeing its tools discovered:

mcp_server_oauth_add_authorize_flow.mp4

Adding, connecting, and managing a plain (no-auth) MCP server:

mcp_server_add_connect_manage_ui.mp4

OAuth server parked in authorization-required state with authorize link
OAuth server connected with discovered secret_number tool

What's included

  • McpClientHub Durable Object (one per user) owning the Cloudflare Agents SDK MCPClientManager; server registrations, OAuth client registrations, and tokens persist in DO SQLite storage. The hub constructs a DurableObjectOAuthClientProvider per server registration so OAuth-protected servers surface an authorization URL (the SDK's registerServer does not create one on its own).
  • D1 mcp_server_settings table (migration 0053) for user-scoped metadata (name, url, enabled) so the registry can list servers without waking the DO; per-user snapshot cache (30s TTL) in front of the DO.
  • OAuth flow: adding a protected server parks in authenticating with an authUrl; the browser callback at /account/mcp-servers/oauth/callback is authenticated via the session cookie and forwarded to that user's hub, which completes the code exchange and connects. Remote-only: server URLs must be https (http allowed for loopback in local dev).
  • Capability synthesis: enabled + connected servers surface as mcp:<server> domains with one capability per tool (mcp:<server>:<tool>, source: 'mcp-server'), discoverable via search with exact kody.mcp[...] accessors.
  • Executor: kody.mcp proxy (mirroring kody.remote) in the execute runtime and package app runtime, with helpful errors for unknown servers/tools and disconnected servers.
  • Management capabilities: mcp_server_add, mcp_server_list, mcp_server_reconnect, mcp_server_refresh, mcp_server_remove, mcp_server_set_enabled.
  • UI: /account/mcp-servers page (add form, live status, authorize link, discovered tools, reconnect/refresh/enable/disable/remove) linked from the account page and top nav.
  • Account lifecycle: mcp_server_settings covered in account export and deletion; the hub DO is purged on account deletion.
  • Docs: new docs/contributing/architecture/mcp-client-servers.md; primitives map updated.

Testing

  • npm run validate passes (format, lint, typecheck, 611 unit tests, Playwright E2E, MCP E2E).
  • Manual E2E against the dev server with local test MCP servers:
    • Plain server: added via UI and via mcp_server_add capability; tools discovered; kody.mcp["test-tools"].add_numbers({a:20,b:22}) returns {sum: 42} through the real /mcp execute path; unknown-server error path returns a helpful message.
    • OAuth server: added via UI → parked in authenticating with authorize link → browser authorization → callback → connected with tools discovered → kody.mcp["oauth-tools"].secret_number({}) returns {secret: 1234} through execute.
    • Execute log from the /mcp end-to-end check: kody_mcp_execute_e2e.log
System recap — adds a new primitive (high risk)

Mode: recap · Base: main @ 8fa6526d · Head: 13c44f07

Classification: adds — introduces the mcp-client-servers primitive (per-user MCP client hub DO + D1 settings + synthesized kody.mcp domains). primitives.yaml is updated in this PR.

Primitives touched

Primitive Group Impact
mcp-client-servers assistant adds — new primitive (hub DO, settings, OAuth callback, mcp_servers domain)
capability-registry assistant extends — runtime merge now synthesizes mcp:<server> domains
capabilities-execute runtime extends — new kody.mcp proxy beside kody.remote
app-ui surfaces extends — new /account/mcp-servers routes + OAuth callback route
package-runtime runtime extends — package-app kody proxy gains kody.mcp
d1-app-db storage extends — new mcp_server_settings table (migration 0053)
account-export assistant composes — new table added to export/deletion targets

System map

flowchart LR
	appUi["app-ui"]:::extended
	mcpServer["mcp-server (/mcp)"]:::untouched
	capabilityRegistry["capability-registry"]:::extended
	capabilitiesExecute["capabilities-execute"]:::extended
	packageRuntime["package-runtime"]:::extended
	mcpClientServers["mcp-client-servers"]:::added
	d1AppDb["d1-app-db"]:::extended
	remoteConnectors["remote-connectors"]:::untouched
	appUi --> mcpClientServers
	mcpServer --> capabilityRegistry
	capabilityRegistry --> mcpClientServers
	capabilityRegistry --> remoteConnectors
	capabilitiesExecute --> mcpClientServers
	packageRuntime --> capabilitiesExecute
	mcpClientServers --> d1AppDb
	classDef touched fill:#1a7f37,color:#fff
	classDef extended fill:#9a6700,color:#fff
	classDef added fill:#cf222e,color:#fff
	classDef untouched fill:#57606a,color:#fff
Loading

Change flow

sequenceDiagram
	participant U as User (browser)
	participant W as Worker (app routes)
	participant H as McpClientHub DO (per user)
	participant S as Remote MCP server
	U->>W: POST add { name, url }
	W->>H: addServer(callbackUrl)
	H->>S: connect (Agents SDK MCPClientManager)
	S-->>H: 401 + OAuth metadata
	H-->>U: state authenticating + authUrl
	U->>S: authorize in browser
	S->>W: GET /account/mcp-servers/oauth/callback?code&state
	W->>H: handleOAuthCallback(url) (session-cookie scoped)
	H->>S: token exchange + connect + discover tools
	W-->>U: 303 /account/mcp-servers?auth=success
Loading

Invariants

  • per-user-isolation: hub DO id is derived from the stable MCP userId; mcp_server_settings reads/writes filter by user_id; the OAuth callback resolves the hub through the authenticated session cookie, so state lookups never cross users; registry synthesis only reads the calling user's servers.
  • compact-mcp-surface: no new top-level MCP tools; management lands as capabilities behind search/execute, and server tools land as synthesized domains.
  • no-secrets-in-chat: OAuth tokens live only in hub DO storage; they are never returned in snapshots, capability results, or the UI payloads.
Open in Web Open in Cursor 

Summary by CodeRabbit

  • New Features
    • Added an MCP servers section in Account settings with a dedicated navigation link and interactive management page.
    • Users can add, reconnect, refresh, enable/disable, and remove remote MCP servers, including an OAuth connect flow that returns to the page.
    • Enabled MCP servers are now reflected in capability listings and are invocable via kody.mcp[...] tooling and mcp_servers capabilities.
  • Bug Fixes
    • Improved MCP server name normalization and URL validation (including stricter handling of non-HTTPS hosts).
    • Account cleanup now purges MCP server connections.
  • Documentation
    • Expanded architecture and contributing docs for MCP client servers.
  • Tests
    • Added test coverage for MCP server helpers, hub/snapshot/capability synthesis behavior, and Account MCP server endpoints.

@coderabbitai

coderabbitai Bot commented Jul 8, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: dbb35209-c1fe-4605-84cf-57768bbbd51e

📥 Commits

Reviewing files that changed from the base of the PR and between 4569b5e and 72651ea.

📒 Files selected for processing (1)
  • packages/worker/src/mcp/capabilities/mcp-server/index.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • packages/worker/src/mcp/capabilities/mcp-server/index.ts

📝 Walkthrough

Walkthrough

Adds user-managed remote MCP client servers end to end: shared validation and ID helpers, persistent per-user hub/runtime support, capability synthesis and execution wiring, account UI/API routes, deletion cleanup, and documentation.

Changes

MCP Client Servers Feature

Layer / File(s) Summary
Docs and primitives
docs/contributing/adding-capabilities.md, docs/contributing/architecture/index.md, docs/contributing/architecture/mcp-client-servers.md, docs/contributing/architecture/primitives.yaml
Adds MCP client server architecture docs and catalog entries.
Shared naming and ID helpers
packages/shared/src/mcp-servers.ts, packages/shared/src/mcp-servers.node.test.ts, packages/worker/src/mcp-client/mcp-domain-id.ts, packages/worker/src/mcp-client/mcp-domain-id.node.test.ts
Adds MCP server naming, URL validation, and deterministic domain/tool/capability ID helpers with tests.
Storage, env bindings, and deletion cleanup
packages/worker/migrations/0053-mcp-server-settings.sql, packages/worker/src/env-schema.ts, packages/worker/worker-configuration.d.ts, packages/worker/wrangler.jsonc, packages/worker/src/index.ts, packages/worker/src/app/account-data-targets.ts, packages/worker/src/app/account-deletion.ts, packages/worker/src/app/account-deletion.node.test.ts, packages/worker/src/execute-maintenance.ts, packages/worker/src/execute-maintenance.node.test.ts, packages/worker/src/app/handler.node.test.ts, packages/worker/src/app/ssr-render.node.test.ts, packages/worker/src/oauth-handlers.workers.test.ts
Adds the mcp_server_settings table, MCP_CLIENT_HUB bindings, worker exports, account-scoped cleanup, and test env updates.
McpClientHub runtime and cache
packages/worker/src/mcp-client/hub.ts, packages/worker/src/mcp-client/hub-client.ts, packages/worker/src/mcp-client/settings-repo.ts, packages/worker/src/mcp-client/settings-service.ts, packages/worker/src/mcp-client/status.ts, packages/worker/src/mcp-client/types.ts, packages/worker/src/mcp-client/settings-types.ts
Implements the per-user hub DO, cached client wrapper, D1 repository, settings service, status helpers, and supporting types.
Capability model and registry plumbing
packages/worker/src/mcp/capabilities/types.ts, packages/worker/src/mcp/capabilities/domain-metadata.ts, packages/worker/src/mcp/capabilities/define-capability.ts, packages/worker/src/mcp/capabilities/build-capability-registry.ts, packages/worker/src/mcp/capabilities/builtin-domains.ts, packages/worker/src/mcp/capabilities/registry.ts, packages/worker/src/mcp/capabilities/meta/meta-list-capabilities.ts
Extends capability types, metadata, and registry output to carry MCP server provenance.
Synthesized MCP server and management capabilities
packages/worker/src/mcp/capabilities/mcp-server/index.ts, packages/worker/src/mcp/capabilities/mcp-server/synthesize.node.test.ts, packages/worker/src/mcp/capabilities/mcp-servers/domain.ts, packages/worker/src/mcp/capabilities/mcp-servers/mcp-server-add.ts, packages/worker/src/mcp/capabilities/mcp-servers/mcp-server-list.ts, packages/worker/src/mcp/capabilities/mcp-servers/mcp-server-reconnect.ts, packages/worker/src/mcp/capabilities/mcp-servers/mcp-server-refresh.ts, packages/worker/src/mcp/capabilities/mcp-servers/mcp-server-remove.ts, packages/worker/src/mcp/capabilities/mcp-servers/mcp-server-set-enabled.ts, packages/worker/src/mcp/capabilities/mcp-servers/shared.ts
Adds synthesized mcp:<server> domains and the mcp_servers management capabilities.
Executor and search wiring for kody.mcp[...]
packages/worker/src/mcp/kody-remote-types.ts, packages/worker/src/mcp/kody-remote-proxy-source.ts, packages/worker/src/mcp/executor.ts, packages/worker/src/mcp/run-kody-registry.ts, packages/worker/src/mcp/server-instructions.ts, packages/worker/src/mcp/tools/search-format.ts, packages/worker/src/mcp/tools/search.ts, packages/worker/src/package-runtime/package-app.ts, packages/worker/src/execute-maintenance.ts, packages/worker/src/execute-maintenance.node.test.ts
Adds the kody.mcp[...] namespace, threads MCP server metadata through provider and search paths, and updates instruction text.
Account MCP servers UI, API, and routing
packages/worker/src/app/account-mcp-servers-data.ts, packages/worker/src/app/handlers/account-mcp-servers.ts, packages/worker/src/app/router.ts, packages/worker/src/app/routes.ts, packages/worker/src/app/loader-data.ts, packages/worker/client/routes/account-mcp-servers.tsx, packages/worker/client/routes/account.tsx, packages/worker/client/routes/index.tsx, packages/worker/client/app.tsx
Adds the account MCP servers page, API/OAuth handlers, client route wiring, loader data, and navigation entry points.

Estimated code review effort: 5 (Critical) | ~120 minutes

Sequence Diagram(s)

sequenceDiagram
  participant AccountMcpServersRoute
  participant AccountMcpServersApiHandler
  participant SettingsService
  participant McpClientHub

  AccountMcpServersRoute->>AccountMcpServersApiHandler: POST { action: "add", name, url }
  AccountMcpServersApiHandler->>SettingsService: addMcpServer(userId, name, url, baseUrl)
  SettingsService->>McpClientHub: addServer(...)
  McpClientHub-->>SettingsService: connectResult
  SettingsService-->>AccountMcpServersApiHandler: setting + connection
  AccountMcpServersApiHandler-->>AccountMcpServersRoute: JSON { servers, selectedServerId }
Loading
sequenceDiagram
  participant GeneratedCode
  participant PackageAppProxy
  participant RuntimeBridge
  participant McpClientHub
  participant RemoteServer

  GeneratedCode->>PackageAppProxy: kody.mcp["linear"].create_issue(args)
  PackageAppProxy->>RuntimeBridge: callCapability("mcp:linear:create_issue", args)
  RuntimeBridge->>McpClientHub: callTool(serverId, toolName, args)
  McpClientHub->>RemoteServer: forward tool call
  RemoteServer-->>McpClientHub: CallToolResult
  RuntimeBridge-->>GeneratedCode: structuredContent / content
Loading

Possibly related PRs

  • kentcdodds/kody#605: Both PRs modify the same capability registry cache and synthesis flow in packages/worker/src/mcp/capabilities/registry.ts.
  • kentcdodds/kody#630: Both PRs modify the Kody proxy/executor generation path in packages/worker/src/mcp/executor.ts and packages/worker/src/mcp/kody-remote-proxy-source.ts.
  • kentcdodds/kody#418: Both PRs extend the per-user account deletion cascade in packages/worker/src/app/account-deletion.ts.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely summarizes the main change: adding MCP client support for user-added remote MCP servers.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/remote-mcp-servers-baf1

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@kentcdodds
kentcdodds marked this pull request as ready for review July 8, 2026 03:55
@github-actions

github-actions Bot commented Jul 8, 2026 •

Copy link
Copy Markdown
Contributor

🔎 Preview deployed: https://kody-pr-662.kody-a99.workers.dev

Worker: kody-pr-662
D1: kody-pr-662-db
KV: kody-pr-662-oauth-kv

Mocks:

Comment thread packages/worker/src/app/account-deletion.ts Outdated
Comment thread packages/worker/src/mcp-client/settings-service.ts Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🧹 Nitpick comments (3)
packages/worker/src/mcp/tools/search.ts (1)

298-305: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

Accessor-building logic duplicates buildNamespacedKodyAccessor from search-format.ts.

The regex check and JSON.stringify accessor construction for mcp-server mirrors the same pattern already duplicated for remote-connector (lines 290-296). Consider exporting buildNamespacedKodyAccessor from search-format.ts and reusing it here to keep accessor generation in one place.

♻️ Optional refactor

In search-format.ts, export the helper:

-export function buildNamespacedKodyAccessor(input: {
+export function buildNamespacedKodyAccessor(input: {

Then in search.ts, replace the manual accessor construction:

 		if (topMatch.source === 'mcp-server' && topMatch.mcpServer) {
-			const serverName = topMatch.mcpServer.kodyName
-			const toolName = topMatch.mcpServer.toolName
-			const accessor = /^[A-Za-z_$][\w$]*$/.test(toolName)
-				? `kody.mcp[${JSON.stringify(serverName)}].${toolName}`
-				: `kody.mcp[${JSON.stringify(serverName)}][${JSON.stringify(toolName)}]`
+			const accessor = buildNamespacedKodyAccessor({
+				namespace: 'mcp',
+				entryName: topMatch.mcpServer.kodyName,
+				toolName: topMatch.mcpServer.toolName,
+			})
 			return `Inspect capability detail with \`search({ entity: "${topMatch.name}:capability" })\` to confirm the TypeScript call shape, then call it from \`execute\` via \`${accessor}(args)\`.`
 		}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/worker/src/mcp/tools/search.ts` around lines 298 - 305, The accessor
construction in the mcp-server branch of search formatting is duplicating the
same namespaced accessor logic already handled by buildNamespacedKodyAccessor in
search-format.ts. Export and reuse buildNamespacedKodyAccessor from
search-format.ts, then update search.ts to call that helper for the mcp-server
path instead of rebuilding the regex and JSON.stringify accessor inline, keeping
accessor generation centralized alongside the existing remote-connector usage.
packages/worker/src/mcp/capabilities/mcp-server/index.ts (1)

85-99: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

Consider extracting a helper for repeated annotation access.

The same (tool.annotations as Record<string, unknown> | undefined)?.['...'] pattern is used three times for readOnlyHint, idempotentHint, and destructiveHint. A small helper like getAnnotationFlag(tool, key) would reduce duplication and the repeated cast.

♻️ Optional refactor
+function getAnnotationFlag(
+	tool: McpServerToolDescriptor,
+	key: string,
+): boolean {
+	return Boolean(
+		(tool.annotations as Record<string, unknown> | undefined)?.[key],
+	)
+}
+
 function createCapabilityFromTool(input: {
 	// ...
 }) {
 	// ...
 		readOnly: getAnnotationFlag(tool, 'readOnlyHint'),
 		idempotent: getAnnotationFlag(tool, 'idempotentHint'),
 		destructive: getAnnotationFlag(tool, 'destructiveHint'),
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/worker/src/mcp/capabilities/mcp-server/index.ts` around lines 85 -
99, The annotation lookup in the MCP server tool capability mapping repeats the
same cast-and-index pattern for readOnlyHint, idempotentHint, and
destructiveHint. Extract a small helper such as getAnnotationFlag(tool, key)
near the mapping logic in mcp-server/index.ts, and use it for the readOnly,
idempotent, and destructive fields to centralize the annotations access and
remove duplication.
packages/worker/src/app/handlers/account-mcp-servers.node.test.ts (1)

142-281: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Add tests for reconnect and refresh actions.

The test suite covers add, set-enabled, delete, and OAuth callback, but does not exercise the reconnect or refresh actions. These actions involve requireSetting ownership checks and hub client calls (reconnectServer/refreshServer) that should be verified. The mock for createMcpClientHubClient also only includes handleOAuthCallback — adding reconnectServer and refreshServer mocks would be needed.

Additionally, the add-action test (lines 175–206) only asserts ok and selectedServerId on the response payload. It does not verify the servers array or whether the authUrl from the connection result is available to the client. Consider asserting the full response shape to catch regressions in the add flow.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/worker/src/app/handlers/account-mcp-servers.node.test.ts` around
lines 142 - 281, The MCP servers handler tests are missing coverage for the
reconnect and refresh actions, and the add-action assertion is too narrow.
Extend the mock returned by createMcpClientHubClient to include reconnectServer
and refreshServer, then add tests in account-mcp-servers.node.test.ts that
exercise the createAccountMcpServersApiHandler POST paths for reconnect and
refresh, verifying requireSetting ownership checks and the expected hub client
calls. Also strengthen the add-action test around
createAccountMcpServersApiHandler by asserting the full response payload from
the add flow, including the servers array and any authUrl returned from the
connection result, so regressions in the response shape are caught.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@packages/worker/src/mcp-client/settings-service.ts`:
- Around line 114-134: The MCP server setup flow leaves an orphaned Durable
Object registration if the D1 persistence step fails after hub.addServer
succeeds. Update the add-server path in settings-service.ts so
insertMcpServerSettingRow is wrapped in its own try/catch after the
hub.addServer call, and on failure call hub.removeServer using the
connection/server identifier before rethrowing. Keep the cleanup local to the
existing connection setup logic so the hub.addServer and
insertMcpServerSettingRow sequence stays easy to follow.

In `@packages/worker/src/mcp/capabilities/mcp-server/index.ts`:
- Around line 128-142: The catch block in MCP server tool execution is
overwriting the original `hub.callTool` failure if `getMcpServerStatus` throws.
Update the `try/catch` around the `hub.callTool` path in `McpServerCapability`
so the status lookup is wrapped in its own `try/catch`, and if status retrieval
fails, fall back to rethrowing the original tool error with the existing
`ref.name`, `tool.name`, and error-message formatting logic.

---

Nitpick comments:
In `@packages/worker/src/app/handlers/account-mcp-servers.node.test.ts`:
- Around line 142-281: The MCP servers handler tests are missing coverage for
the reconnect and refresh actions, and the add-action assertion is too narrow.
Extend the mock returned by createMcpClientHubClient to include reconnectServer
and refreshServer, then add tests in account-mcp-servers.node.test.ts that
exercise the createAccountMcpServersApiHandler POST paths for reconnect and
refresh, verifying requireSetting ownership checks and the expected hub client
calls. Also strengthen the add-action test around
createAccountMcpServersApiHandler by asserting the full response payload from
the add flow, including the servers array and any authUrl returned from the
connection result, so regressions in the response shape are caught.

In `@packages/worker/src/mcp/capabilities/mcp-server/index.ts`:
- Around line 85-99: The annotation lookup in the MCP server tool capability
mapping repeats the same cast-and-index pattern for readOnlyHint,
idempotentHint, and destructiveHint. Extract a small helper such as
getAnnotationFlag(tool, key) near the mapping logic in mcp-server/index.ts, and
use it for the readOnly, idempotent, and destructive fields to centralize the
annotations access and remove duplication.

In `@packages/worker/src/mcp/tools/search.ts`:
- Around line 298-305: The accessor construction in the mcp-server branch of
search formatting is duplicating the same namespaced accessor logic already
handled by buildNamespacedKodyAccessor in search-format.ts. Export and reuse
buildNamespacedKodyAccessor from search-format.ts, then update search.ts to call
that helper for the mcp-server path instead of rebuilding the regex and
JSON.stringify accessor inline, keeping accessor generation centralized
alongside the existing remote-connector usage.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: ae470f11-b3ee-4648-b3a1-7d7dfc1234bf

📥 Commits

Reviewing files that changed from the base of the PR and between 8fa6526 and 13c44f0.

📒 Files selected for processing (62)
  • docs/contributing/adding-capabilities.md
  • docs/contributing/architecture/index.md
  • docs/contributing/architecture/mcp-client-servers.md
  • docs/contributing/architecture/primitives.yaml
  • packages/shared/src/mcp-servers.node.test.ts
  • packages/shared/src/mcp-servers.ts
  • packages/worker/client/app.tsx
  • packages/worker/client/routes/account-mcp-servers.tsx
  • packages/worker/client/routes/account.tsx
  • packages/worker/client/routes/index.tsx
  • packages/worker/migrations/0053-mcp-server-settings.sql
  • packages/worker/src/app/account-data-targets.ts
  • packages/worker/src/app/account-deletion.ts
  • packages/worker/src/app/account-mcp-servers-data.ts
  • packages/worker/src/app/handler.node.test.ts
  • packages/worker/src/app/handlers/account-mcp-servers.node.test.ts
  • packages/worker/src/app/handlers/account-mcp-servers.ts
  • packages/worker/src/app/loader-data.ts
  • packages/worker/src/app/router.ts
  • packages/worker/src/app/routes.ts
  • packages/worker/src/app/ssr-render.node.test.ts
  • packages/worker/src/env-schema.ts
  • packages/worker/src/execute-maintenance.node.test.ts
  • packages/worker/src/execute-maintenance.ts
  • packages/worker/src/index.ts
  • packages/worker/src/mcp-client/hub-client.ts
  • packages/worker/src/mcp-client/hub.ts
  • packages/worker/src/mcp-client/mcp-domain-id.node.test.ts
  • packages/worker/src/mcp-client/mcp-domain-id.ts
  • packages/worker/src/mcp-client/settings-repo.ts
  • packages/worker/src/mcp-client/settings-service.ts
  • packages/worker/src/mcp-client/settings-types.ts
  • packages/worker/src/mcp-client/status.ts
  • packages/worker/src/mcp-client/types.ts
  • packages/worker/src/mcp/capabilities/build-capability-registry.ts
  • packages/worker/src/mcp/capabilities/builtin-domains.ts
  • packages/worker/src/mcp/capabilities/define-capability.ts
  • packages/worker/src/mcp/capabilities/domain-metadata.ts
  • packages/worker/src/mcp/capabilities/mcp-server/index.ts
  • packages/worker/src/mcp/capabilities/mcp-server/synthesize.node.test.ts
  • packages/worker/src/mcp/capabilities/mcp-servers/domain.ts
  • packages/worker/src/mcp/capabilities/mcp-servers/mcp-server-add.ts
  • packages/worker/src/mcp/capabilities/mcp-servers/mcp-server-list.ts
  • packages/worker/src/mcp/capabilities/mcp-servers/mcp-server-reconnect.ts
  • packages/worker/src/mcp/capabilities/mcp-servers/mcp-server-refresh.ts
  • packages/worker/src/mcp/capabilities/mcp-servers/mcp-server-remove.ts
  • packages/worker/src/mcp/capabilities/mcp-servers/mcp-server-set-enabled.ts
  • packages/worker/src/mcp/capabilities/mcp-servers/shared.ts
  • packages/worker/src/mcp/capabilities/meta/meta-list-capabilities.ts
  • packages/worker/src/mcp/capabilities/registry.ts
  • packages/worker/src/mcp/capabilities/types.ts
  • packages/worker/src/mcp/executor.ts
  • packages/worker/src/mcp/kody-remote-proxy-source.ts
  • packages/worker/src/mcp/kody-remote-types.ts
  • packages/worker/src/mcp/run-kody-registry.ts
  • packages/worker/src/mcp/server-instructions.ts
  • packages/worker/src/mcp/tools/search-format.ts
  • packages/worker/src/mcp/tools/search.ts
  • packages/worker/src/oauth-handlers.workers.test.ts
  • packages/worker/src/package-runtime/package-app.ts
  • packages/worker/worker-configuration.d.ts
  • packages/worker/wrangler.jsonc

Comment thread packages/worker/src/mcp-client/settings-service.ts
Comment thread packages/worker/src/mcp/capabilities/mcp-server/index.ts
await this.manager.waitForConnections({
timeout: connectionSettleTimeoutMs,
})
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

OAuth path skips tool discovery

Medium Severity

After a successful MCP OAuth callback, the hub calls establishConnection and waitForConnections but never runs discoverIfConnected, unlike addServer and successful reconnectServer paths. If discovery is not finished when waiting ends, the server can stay non-ready with no tools, so synthesized kody.mcp capabilities and the account UI may show authorization success without callable tools until reconnect or refresh.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 4569b5e. Configure here.

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

There are 2 total unresolved issues (including 1 from previous review).

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 72651ea. Configure here.

const state = this.connectionStateFor(input.serverId)
if (state === 'disconnected') {
throw new Error(`MCP server "${input.serverId}" is not registered.`)
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reconnect fails after hub-only removal

Medium Severity

deleteMcpServer removes the hub registration before the D1 row. If the database delete fails, settings still list the server but the hub no longer registers it. reconnectServer then treats that as “not registered” and errors instead of re-registering from saved URL and OAuth callback settings.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 72651ea. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants