From 9542348ebf5ac9d7cc9a7a12981b821f38d1e485 Mon Sep 17 00:00:00 2001 From: "molecule-ai[bot]" <276602405+molecule-ai[bot]@users.noreply.github.com> Date: Fri, 17 Apr 2026 22:06:05 +0000 Subject: [PATCH] fix(opencode): add full MCP path to opencode.json URL Security Auditor FINDING-1: bare ${MOLECULE_MCP_URL} missing the router path. Fix adds /workspaces/${WORKSPACE_ID}/mcp so opencode reaches MCPHandler. Unblocks PR#842 merge. --- org-templates/molecule-dev/opencode.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/org-templates/molecule-dev/opencode.json b/org-templates/molecule-dev/opencode.json index 59a383de..acfbe34d 100644 --- a/org-templates/molecule-dev/opencode.json +++ b/org-templates/molecule-dev/opencode.json @@ -2,7 +2,7 @@ "mcpServers": { "molecule": { "type": "remote", - "url": "${MOLECULE_MCP_URL}", + "url": "${MOLECULE_MCP_URL}/workspaces/${WORKSPACE_ID}/mcp", "headers": { "Authorization": "Bearer ${MOLECULE_MCP_TOKEN}" }, "description": "Molecule AI A2A orchestration — delegate_task, list_peers, check_task_status" }