node: follow MCP tool-list pagination in discovery and remote tool lookups - #566
bodapatisaikrishna wants to merge 1 commit into
Conversation
…okups Drain the MCP Tools iterator instead of single-page ListTools across discovery and find_remote_tools, and stream describe_remote_tool with early return. Cap per-service tool drain at 256 to bound against hostile endless cursor loops under zero trust.
There was a problem hiding this comment.
Code Review
This pull request introduces a limit on the number of tools collected per service (capped at 256) to prevent issues with endless cursor loops or extremely large catalogues. It refactors the tool fetching logic to use a new listAllTools helper and adds comprehensive unit tests covering pagination and endless cursor scenarios. The review feedback suggests adding a debug log when truncating the tool search in fetchRemoteToolDescription for consistency and better troubleshooting.
| if count >= maxToolsPerService { | ||
| break | ||
| } |
There was a problem hiding this comment.
For consistency with listAllTools and to aid in troubleshooting, consider logging a debug message when the tool search is truncated due to reaching the maxToolsPerService cap. This helps operators understand if a tool lookup failed because the tool list was truncated.
if count >= maxToolsPerService {
logger.Debugf("reached cap of %d tools while searching for %q; truncating", maxToolsPerService, toolName)
break
}
Fixes #444
MCP backends with large catalogues paginate
tools/listresponses across multiple pages using cursors. Discovery and remote tool lookups previously usedListTools(), which only inspects the first page.This drains the SDK's
Toolsiterator inTools()andfetchToolsForRemoteService, and streamssession.ToolsinfetchRemoteToolDescriptionwith early return once a match is found. Under zero trust, per-service tool drain is capped at 256 to guard against endless cursor loops and excessive memory usage from hostile peers.