Skip to content

Reject unusable MCP process and HTTP transport values #518

Description

@devantler

🤖 Generated by the Agentic Engineer

Problem and evidence

The package gate accepts MCP transport values that native process and HTTP APIs refuse. Complete offline packages containing unusable process strings or HTTP header fields pass manifest validation, but the corresponding native API rejects them before a usable connection can exist.

Expected outcome

Validate supported process strings and HTTP header names/values at the transport boundary so a green package gate represents a configuration the consumer can use.

Acceptance criteria

  • Reproduce acceptance through the actual package gate and refusal through native APIs without starting a server or making a network request.
  • Reject embedded NUL in process command, arguments and environment fields.
  • Validate HTTP header field names and values against their wire syntax.
  • Preserve legitimate empty arguments/values, Unicode process strings, literal variable references and permitted header whitespace.
  • Run MCP and manifest regression suites.

Rough size: S. Part of #223.

Activity

  1. added theissue type on Oct 5, 2026
  2. self-assigned this
    on Oct 5, 2026
  3. added a commit that references this issue on Oct 5, 2026
  4. devantler commented on Oct 5, 2026

    @devantler
    ContributorAuthor

    🤖 Generated by the Agentic Engineer

    Delivered in #521. Package validation now preserves original JSON bytes and rejects unusable command, argument, environment and HTTP header values before installation. Supported Unicode, empty values and literal variable references remain accepted.

    The package gate passes all 433 cases, and the offline evaluation against native Node HTTP/process validation passes all 522 controls. No network request or configured MCP process is needed for that evaluation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

Fields

Priority

None yet

Effort

None yet

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions