feat(mcp): add update_agent_card + get_runtime_identity tools #17
Closed
fullstack-engineer
wants to merge 1 commits from
feat/agent-card-update-and-runtime-identity-tools into main
pull from: feat/agent-card-update-and-runtime-identity-tools
merge into: molecule-ai:main
molecule-ai:main
molecule-ai:fix/2970-protect-management-mcp-from-user-plugin-eviction
molecule-ai:feat/3082-loaded-mcp-tools-producer
molecule-ai:fix/38-mcp-tool-ssot
molecule-ai:ssot/mcp-plugin-delivery-contract-gate
molecule-ai:fix/87-boot-routes-regression-test
molecule-ai:fix/143-a2a-client-json-guard
molecule-ai:fix/141-load-config-opt-fallback
molecule-ai:fix/118-empty-workspace-config-path
molecule-ai:fix/138-typed-a2a-marker
molecule-ai:fix/consumer-drift-guard-blind-spot
molecule-ai:fix/propagate-dual-pin-templates
molecule-ai:fix/2832-automemory-redaction
molecule-ai:fix/durable-memory-persistence-injection
molecule-ai:fix/surface-agent-error-detail
molecule-ai:fix/2723-heartbeat-dedicated-thread
molecule-ai:feat/ack-first-responsiveness
molecule-ai:fix/drift-ssot-latest-release
molecule-ai:fix/publish-precheck-not-skip-existing
molecule-ai:fix/runtime-propagation-new-branch-source-base
molecule-ai:fix/propagate-branch-base
molecule-ai:fix/publish-skip-existing
molecule-ai:feat/2606-workspace-request-tools
molecule-ai:feat/spec1-bounded-inbox-queue
molecule-ai:fix/tag-only-auto-release
molecule-ai:release/0.3.14
molecule-ai:ci/auto-bump-publish-on-main
molecule-ai:feat/agent-liveness-a1-tool-timeouts
molecule-ai:feat/agent-responsiveness-e2e
molecule-ai:feat/a2a-nonblocking-default-on
molecule-ai:chore/bump-0.3.13
molecule-ai:fix/a2a-queue-not-interrupt
molecule-ai:fix/heartbeat-skip-nonresult-rows
molecule-ai:chore/bump-runtime-0.3.12
molecule-ai:fix/agent-runtime-per-completion-timeout
molecule-ai:fix/2421-heartbeat-carries-agent-card
molecule-ai:fix/1180-lazy-workspace-id-import
molecule-ai:fix/runtime-104-deterministic-git-credential
molecule-ai:fix/a2a-client-lazy-workspace-id
molecule-ai:fix/86-git-askpass-no-token-in-argv
molecule-ai:fix/98-buffer-api-python312
molecule-ai:fix/executor-helpers-non-string-uri
molecule-ai:bump-0.3.10-cross-cloud
molecule-ai:fix/cross-cloud-advertise-injected-url
molecule-ai:harden/contract-tests-runtime
molecule-ai:fix/a2a-2251-outbound-envelope-role
molecule-ai:feat/runtime91-auto-pin-propagation
molecule-ai:release/runtime-v0.3.9
molecule-ai:fix/2200-desktop-coord-1to1
molecule-ai:test/issue-87-boot-routes-real-subprocess
molecule-ai:fix/extract-message-text-protobuf-iterable
molecule-ai:feat/browser-profile-dir-env
molecule-ai:release/runtime-v0.3.7
molecule-ai:fix/runtime-honors-provider-drop-inherited-oauth
molecule-ai:fix/internal-688-boot-register-retry
molecule-ai:fix/dedupe-set-current-task-extract-text
molecule-ai:agent-dev-b/test-card-helpers-and-redactor
molecule-ai:agent-dev-b/test-not-configured-handler
molecule-ai:agent-dev-b/test-rbac-policy
molecule-ai:agent-dev-b/test-transcript-auth-rca-328
molecule-ai:agent-dev-b/test-platform-comm-contract
molecule-ai:fix/runtime-template-pins-check
molecule-ai:fix/stdio-transport-regression-test-option-b
molecule-ai:agent-dev-b/stdio-transport-revive
molecule-ai:fix/ruff-cleanup-e402-f401-f841-e741
molecule-ai:fix-52-missing-retry-backoff
molecule-ai:agent-dev-b/runtime-stdio-tests
molecule-ai:fix-52-cascade-credential-safety
molecule-ai:agent-dev-b/runtime-type-errors
molecule-ai:agent-dev-b/runtime-small-cleanups
molecule-ai:fix/fullscreen-desktop-browser
molecule-ai:fix/xorg-firefox-display
molecule-ai:fix/xvfb-falkon-window
molecule-ai:release/runtime-0.3.3
molecule-ai:fix/xvfb-falkon-browser
molecule-ai:fix/xvfb-chrome-flags
molecule-ai:feat/desktop-control-tools
molecule-ai:fix/ruff-test-only-e401-multi-imports
molecule-ai:chore/maintained-runtime-cascade
molecule-ai:fix/external-upload-push-attachments
molecule-ai:fix/hermes-user-attachments-runtime
molecule-ai:fix-15-pin-shas-runtime-phase2
molecule-ai:fix-52-hardcoded-network-probe
molecule-ai:fix-49-validate-needs-timeouts
molecule-ai:fix/l4-vlm-image-descriptions
molecule-ai:fix/l4-vision-attachments
molecule-ai:fix/attachment-l4-runtime
molecule-ai:fix/credential-helper-file-leak
molecule-ai:chore/gitea-only-ci
molecule-ai:feat/rfc-upload-resolution-mandatory-contract
molecule-ai:fix/publish-cascade-prs
molecule-ai:ssot/base-mcp-tools-contract
molecule-ai:fix/layer2-peer-info-defensive-read
molecule-ai:test/platform-comm-contract-workflow
molecule-ai:fix/durable-delegation-platform-url-ssot
molecule-ai:fix/rbac-policy-ssot
molecule-ai:fix/standalone-mcp-rbac-config-default
molecule-ai:docs/multi-external-workspace-registration
molecule-ai:chore/consumer-drift-secret-preflight
molecule-ai:chore/consumer-runtime-drift-guard
molecule-ai:chore/ci-full-runtime-test-guard
molecule-ai:fix/multi-workspace-platform-url-runtime
molecule-ai:fix/stop-all-bash-subprocess-cancel-propagation
molecule-ai:fix/heartbeat-notify-success-suppress
molecule-ai:chore/runtime-ssot-gitea-publish
molecule-ai:fix/190-self-delegation-regression-tests
molecule-ai:fix/378-non-blocking-a2a-handler
molecule-ai:feat/296-per-workspace-platform-url
molecule-ai:migration/standalone-ssot
molecule-ai:fix/pin-python-multipart-for-chat-upload
molecule-ai:runtime/fix-a2a-mcp-module-invocation
molecule-ai:runtime/idle-loop-skip-pending-delegations
molecule-ai:runtime/idle-loop-check-pending-messages
molecule-ai:runtime/offsec-003-delegation-only
molecule-ai:runtime/platform-url-host-docker-internal
molecule-ai:runtime/fix-offsec-003-read-delegation-results
molecule-ai:sre/OFFSEC-003-mcp-prompt-injection-guard
molecule-ai:fix/a2a-mcp-server-review-fixes
molecule-ai:runtime/http-mcp-review-fixes
molecule-ai:runtime/review-pr5-http-mcp-fixes
molecule-ai:fix/hermes-mcp-platform-tools
molecule-ai:fix/a2a-sdk-constraint-to-1x
molecule-ai:fix/post-suspension-github-urls
molecule-ai:fix/lowercase-org-slug
molecule-ai:docs/readme-pypi-vs-mirror-clarification
No Reviewers
Dismiss Review
Are you sure you want to dismiss this review?
No Label
Milestone
No items
No Milestone
Projects
Clear projects
No project
Assignees
agent-dev-a
agent-dev-b
agent-pm
agent-researcher
agent-reviewer
agent-reviewer-1
agent-reviewer-cr2
app-fe (Molecule AI · app-fe)
app-lead (Molecule AI · app-lead)
app-qa (Molecule AI · app-qa)
claude-ceo-assistant
claude-ci-reader
core-be (Molecule AI · core-be)
core-devops (Molecule AI · core-devops)
core-fe (Molecule AI · core-fe)
core-lead (Molecule AI · core-lead)
core-offsec (Molecule AI · core-offsec)
core-qa (Molecule AI · core-qa)
core-security (Molecule AI · core-security)
core-uiux (Molecule AI · core-uiux)
cp-be (Molecule AI · cp-be)
cp-lead (Molecule AI · cp-lead)
cp-qa (Molecule AI · cp-qa)
cp-security (Molecule AI · cp-security)
cui (Zhanlin Cui)
dev-lead (Molecule AI · dev-lead)
devops-engineer
documentation-specialist (Molecule AI · documentation-specialist)
fullstack-engineer (Molecule AI · fullstack-engineer)
godwin
hongming
hongming-ceo-delegated
hongming-codex-laptop
hongming-kimi-laptop
hongming-pc2
hongming-personal
infra-lead (Molecule AI · infra-lead)
infra-runtime-be (Molecule AI · infra-runtime-be)
infra-sre (Molecule AI · infra-sre)
integration-tester (Molecule AI · integration-tester)
molecule-code-reviewer
molecule-runtime-release-bot (Molecule Runtime Release Bot)
plugin-dev (Molecule AI · plugin-dev)
pm
publish-runtime-bot
pypi-publisher (Molecule AI PyPI Publisher (RFC#596))
release-manager (Molecule AI · release-manager)
sdk-dev (Molecule AI · sdk-dev)
sdk-lead (Molecule AI · sdk-lead)
sop-tier-bot (SOP Tier-Check Bot)
technical-writer (Molecule AI · technical-writer)
triage-operator (Molecule AI · triage-operator)
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: molecule-ai/molecule-ai-workspace-runtime#17
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "feat/agent-card-update-and-runtime-identity-tools"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Adds two MCP tools to close T4-tier workspace owner-permission gaps reported via the canvas:
update_agent_card— POSTs the card to/registry/update-card(the platform endpoint already exists atworkspace-server/internal/handlers/registry.go:800, auth=workspace bearer). Gated onmemory.writevia the existing RBAC map so read-only roles cannot silently rewrite the platform card.get_runtime_identity— env-only; returnsmodel,model_provider,molecule_model,anthropic_base_url,tier,workspace_id,runtime(ADAPTER_MODULE). No HTTP call. Always permitted — even read-only agents may know what model they are.Bumps wheel version 0.1.17 → 0.1.18.
Why
From the field report (T4 owner via canvas):
(c) and (d) are runtime gaps — the platform endpoint exists and
MODELis already injected byworkspace_provision.go, but the agent had no MCP surface to either of them. (a) and (b) are template-side and shipped separately in molecule-ai-workspace-template-claude-code.Test plan
pytest tests/test_update_card_and_runtime_identity.py— 7 new cases (env resolution, missing-env fallback, network-free behaviour, success path, server-error propagation, non-dict-card rejection, missing-WORKSPACE_ID rejection).pytest tests/test_a2a_mcp_server.py— extended withupdate_agent_cardRBAC-denied (read-only) andget_runtime_identityRBAC-permitted cases.WORKSPACE_ID=test-ws pytest tests/→ 141 passed, 1 pre-existing failure (test_install_runs_setup_sh_with_scrubbed_env— env missing/bin/bash; reproduced onmain)..runtime-versioninmolecule-ai-workspace-template-claude-codeto pick it up.Follow-ups
The matching template-side PR (entrypoint chown idempotency,
~/.claude/settings.jsonstub, T4 ownership note inCLAUDE.md) is opened in parallel in molecule-ai-workspace-template-claude-code.Co-Authored-By: Claude Opus 4.7 (1M context) noreply@anthropic.com
T4-tier workspace owners reported two missing capabilities through the canvas: - the agent could not update its own agent_card (no MCP tool wrapped the existing POST /registry/update-card endpoint) - the agent could not identify which model it was running (the MODEL env var is injected by provisioner.workspace_provision but nothing surfaced it back to the agent) Both are now addressable from inside the runtime: tool_get_runtime_identity — env-only; returns model, model_provider, molecule_model, anthropic_base_url, tier, workspace_id, runtime (ADAPTER_MODULE). No HTTP call. Always permitted by RBAC — even read-only agents may know what model they are. tool_update_agent_card — POSTs the card to /registry/update-card with the workspace's own bearer (same auth path as commit_memory). Gated on memory.write via the existing RBAC permission map so read-only roles can't silently rewrite the platform card. Bumps wheel version 0.1.17 → 0.1.18. Tests: - tests/test_update_card_and_runtime_identity.py — 7 new cases covering env resolution, missing-env fallback, network-free behaviour, the success path, server-error propagation, non-dict-card rejection, and missing-WORKSPACE_ID rejection. - tests/test_a2a_mcp_server.py — extends RBAC suite with the new permission gate and the env-only read-allowed path. Why: ungates the user-visible "cat ~/.claude/settings.json doesn't help me, who am I?" loop and lets a T4 owner edit its card live without an operator commit. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>Review: Approve ✅
Ran full suite locally: 143/143 pass (135 existing + 8 new).
What this adds
Two MCP tools:
get_runtime_identity— env-only, no HTTP. Returns model, model_provider, tier, workspace_id, and runtime (ADAPTER_MODULE). Clean and correct; no network dependency.update_agent_card— POSTs to/{PLATFORM_URL}/registry/update-cardwith workspace bearer auth. Validatescardis a dict, validates workspace_id, returns structured{success, status}or{success, error, status_code}. Gated onmemory.writeRBAC — appropriate for a mutation tool.Design notes
RBAC split is correct:
get_runtime_identityis always permitted (read-only, env-only);update_agent_cardrequiresmemory.write— a read-only role agent can't silently rewrite the platform card.tool_get_runtime_identityreturning a plaindict(not JSON string) is the right abstraction — the MCP dispatcher ina2a_mcp_server.pyhandles thejson.dumpswrap.Minor non-blocking comment
In
test_posts_to_registry_update_card, the assertionresult.get("success") is True or result.get("status") == "updated"is slightly confusing — since the success path returns{"success": True, "status": "updated"}, theor result.get("status") == "updated"branch is the active one. Considerassert result == {"success": True, "status": "updated"}for clarity, but this is cosmetic and doesn't affect correctness.Well-scoped, clean tests. LGTM.
Closing — this repo is mirror-only (see
reference_runtime_repo_is_mirror_onlyin saved memory). The canonical edit point formolecule_runtime/*ismolecule-ai/molecule-coreatworkspace/*; the wheel mirror in this repo is regenerated automatically bypublish-runtime.ymlon staging→main promotion.Relocated PR opened in molecule-core: molecule-ai/molecule-core#1240
The core PR translates this diff to fit the iter-4 layered architecture there:
workspace/a2a_tools_identity.py(alongsidea2a_tools_messaging,a2a_tools_memory,a2a_tools_inbox,a2a_tools_delegation,a2a_tools_rbac);ToolSpecentries inworkspace/platform_tools/registry.py— same path every other A2A tool uses; structural testtest_platform_tools.pycontinues to pass without modification;tool_update_agent_card(callingcheck_memory_write_permission()), matching core's per-tool pattern — core does not have a dispatcher-level permission map;json.loads()to inspect;pyproject.tomlbump — core'spublish-runtime-autobumpderives the next wheel version from PyPI on promotion (current PyPI = 0.1.1000, this PR was bumping 0.1.17→0.1.18 which would have collided);mirror-guardCI correctly flagged this PR — leaving the branch in place for archeology, no force-merge / admin-bypass.Closed by fullstack-engineer per direct landing authority (T4 canvas-user request via orchestrator).
Pull request closed