From e95f39e5d590dae512f5098a9b7822dadde16893 Mon Sep 17 00:00:00 2001 From: Will-hxw <1176843521@qq.com> Date: Tue, 21 Apr 2026 04:35:52 +0800 Subject: [PATCH 1/4] fix(everything): add allowed values to resourceType description The resourceType argument in the resource-prompt was missing a description of allowed values. Added "must be 'Text' or 'Blob'" to help automated callers understand the expected input format. Issue: modelcontextprotocol/servers#3985 Co-Authored-By: Claude Opus 4.7 --- src/everything/resources/templates.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/everything/resources/templates.ts b/src/everything/resources/templates.ts index 6d4903f74c..f56214cba8 100644 --- a/src/everything/resources/templates.ts +++ b/src/everything/resources/templates.ts @@ -25,7 +25,7 @@ export const RESOURCE_TYPES: string[] = [ * The completion logic matches the input against available resource types. */ export const resourceTypeCompleter = completable( - z.string().describe("Type of resource to fetch"), + z.string().describe("Type of resource — must be 'Text' or 'Blob'"), (value: string) => { return RESOURCE_TYPES.filter((t) => t.startsWith(value)); } From f2d1095bd119f47b199daf4a7de23bf799241aa4 Mon Sep 17 00:00:00 2001 From: Will-hxw <1176843521@qq.com> Date: Tue, 21 Apr 2026 04:37:25 +0800 Subject: [PATCH 2/4] fix(everything): require key parameter for get-env tool Prevent leaking all process.env variables by requiring a specific key. This addresses a security concern where the tool was returning the entire environment without any parameter or filtering. Issue: modelcontextprotocol/servers#3986 Co-Authored-By: Claude Opus 4.7 --- src/everything/tools/get-env.ts | 34 ++++++++++++++++++++++++++++----- 1 file changed, 29 insertions(+), 5 deletions(-) diff --git a/src/everything/tools/get-env.ts b/src/everything/tools/get-env.ts index 0adbf5a14d..2cc387c733 100644 --- a/src/everything/tools/get-env.ts +++ b/src/everything/tools/get-env.ts @@ -6,26 +6,50 @@ const name = "get-env"; const config = { title: "Print Environment Tool", description: - "Returns all environment variables, helpful for debugging MCP server configuration", - inputSchema: {}, + "Returns the value of a specific environment variable, helpful for debugging MCP server configuration", + inputSchema: { + type: "object", + properties: { + key: { + type: "string", + description: + "The name of the environment variable to retrieve (e.g., 'PATH', 'HOME', 'USER')", + }, + }, + required: ["key"], + }, }; /** * Registers the 'get-env' tool. * - * The registered tool Retrieves and returns the environment variables - * of the current process as a JSON-formatted string encapsulated in a text response. + * The registered tool retrieves and returns the value of a specific + * environment variable from the current process. * * @param {McpServer} server - The McpServer instance where the tool will be registered. * @returns {void} */ export const registerGetEnvTool = (server: McpServer) => { server.registerTool(name, config, async (args): Promise => { + const { key } = args as { key: string }; + const value = process.env[key]; + + if (value === undefined) { + return { + content: [ + { + type: "text", + text: `Environment variable '${key}' is not set.`, + }, + ], + }; + } + return { content: [ { type: "text", - text: JSON.stringify(process.env, null, 2), + text: `${key}=${value}`, }, ], }; From f81f8819d97989cf7d4a725f9af03fa8e0292fe2 Mon Sep 17 00:00:00 2001 From: Will-hxw <1176843521@qq.com> Date: Tue, 21 Apr 2026 05:49:29 +0800 Subject: [PATCH 3/4] fix(filesystem): CLI directories take precedence over MCP roots When a client supports MCP roots, the server was unconditionally replacing CLI-provided allowed directories with the client's roots. This made it impossible to scope the server to a directory outside the client's project root. Now CLI arguments take precedence - only fetch and apply MCP roots when no CLI directories were provided. Fixes: modelcontextprotocol/servers#3929 Co-Authored-By: Claude Opus 4.7 --- src/filesystem/index.ts | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/src/filesystem/index.ts b/src/filesystem/index.ts index 7b67e63e58..885dedc90b 100644 --- a/src/filesystem/index.ts +++ b/src/filesystem/index.ts @@ -731,7 +731,10 @@ server.server.setNotificationHandler(RootsListChangedNotificationSchema, async ( server.server.oninitialized = async () => { const clientCapabilities = server.server.getClientCapabilities(); - if (clientCapabilities?.roots) { + if (clientCapabilities?.roots && allowedDirectories.length === 0) { + // Only fetch and apply MCP roots when no CLI directories were provided. + // CLI arguments take precedence over MCP roots since they are explicitly + // specified by the server operator. try { const response = await server.server.listRoots(); if (response && 'roots' in response) { @@ -744,7 +747,7 @@ server.server.oninitialized = async () => { } } else { if (allowedDirectories.length > 0) { - console.error("Client does not support MCP Roots, using allowed directories set from server args:", allowedDirectories); + console.error("Client does not support MCP Roots, or CLI directories provided. Using allowed directories from server args:", allowedDirectories); }else{ throw new Error(`Server cannot operate: No allowed directories available. Server was started without command-line directories and client either does not support MCP roots protocol or provided empty roots. Please either: 1) Start server with directory arguments, or 2) Use a client that supports MCP roots protocol and provides valid root directories.`); } From 2be6648ff8fe33a37d55132207453bebe2e7bf61 Mon Sep 17 00:00:00 2001 From: Will-hxw <1176843521@qq.com> Date: Thu, 23 Apr 2026 03:10:18 +0800 Subject: [PATCH 4/4] fix(filesystem): guard roots/list_changed against CLI directory override The roots/list_changed handler was unconditionally replacing allowedDirectories with MCP roots, even when CLI directories were set. Adding the same guard as oninitialized to prevent MCP roots from overriding CLI directories when both are present. --- src/filesystem/index.ts | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/src/filesystem/index.ts b/src/filesystem/index.ts index 885dedc90b..be17182d99 100644 --- a/src/filesystem/index.ts +++ b/src/filesystem/index.ts @@ -717,7 +717,10 @@ async function updateAllowedDirectoriesFromRoots(requestedRoots: Root[]) { // Handles dynamic roots updates during runtime, when client sends "roots/list_changed" notification, server fetches the updated roots and replaces all allowed directories with the new roots. server.server.setNotificationHandler(RootsListChangedNotificationSchema, async () => { try { - // Request the updated roots list from the client + // Only update from MCP roots if no CLI directories were set + if (allowedDirectories.length > 0) { + return; + } const response = await server.server.listRoots(); if (response && 'roots' in response) { await updateAllowedDirectoriesFromRoots(response.roots);