Skip to content

weft does not log what it blocks, and MCP tool calls bypass the guards #2

Description

@dioptx

Two gaps found while building the crew loop in dioptx/agentry.

Nothing records a refusal. A guard that denies a command leaves no trace anywhere, so a builder that was stopped and a builder that never tried look the same afterwards. The agentry events stream (~/.local/state/agentry/events.jsonl) is the place: one guard line per refusal, carrying the tool, the refused input, the rule that fired, and build_id/task from the AGENT_P_TAGS environment, which the loop already sets.

A shell command inside an MCP call is invisible. Guards match Bash, Edit, Write. A tool such as context-mode's ctx_execute takes a shell command as an MCP input and runs it; measured on 2026-09-12, with that plugin's hooks installed Bash never fired once and every command became an MCP call. Any guard that matters must match mcp__* inputs carrying a command the same way it matches Bash.

Spec attempt guard-events was killed by a subscription limit before it ran.

🤖 Generated with Claude Code

https://claude.ai/code/session_019kKcvatxK4kGTK9i15gFxy

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions