You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
add an experimental root specify mcp command using the official Python MCP SDK
expose the compact specify_list_commands, specify_describe_command, and specify_run_command tool surface over stdio only
support only the stable dotted version command and execute specify version --json through an isolated child process using the running CLI's Python environment
propagate the direct version success payload and structured CLI failures without banners, Rich output, fallback success values, or protocol contamination
document the experimental version-only/stdio-only limitations and refresh the committed dependency-audit snapshot
Scope
The supported inventory is deliberately explicit and contains only version. Unsupported commands return an unavailable_command tool error. This change does not expose HTTP/SSE transports, project discovery, artifact commands, mutations, installation/update/removal, workflows, confirmations, access tiers, or generalized timeout/cancellation infrastructure.
The official mcp>=2.2.0,<3.0.0 SDK is a production dependency. Although the SDK brings HTTP/SSE-related transitive packages, specify mcp registers and documents only stdio transport.
collection comparison — 9,552 after versus 9,530 before (+22; no decrease)
uvx ruff@0.15.0 check src tests — passed
uvx --from pip-audit==2.10.0 pip-audit --disable-pip --require-hashes -r .github/security-audit-requirements.txt --progress-spinner off — no known vulnerabilities
real stdio subprocess integration — initialization, tool discovery, direct version execution, unsupported-command error, and empty server stderr all passed
AI assistance
Implemented with GitHub Copilot using GPT-5.6 Sol in autonomous mode; code, tests, documentation, dependency updates, review, and validation were AI-assisted.
Expose the stable version JSON command through an stdio-only MCP server with explicit discovery, subprocess isolation, structured errors, focused tests, and reference documentation.
Assisted-by: GitHub Copilot (model: GPT-5.6 Sol, autonomous)
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Declare Pydantic as a direct runtime dependency and cover schema-invalid success and failure JSON payloads in the subprocess adapter tests.
Assisted-by: GitHub Copilot (model: GPT-5.6 Sol, autonomous)
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
declared pydantic>=2.13.0,<3.0.0 directly in both runtime dependency declarations and regenerated the audit snapshot
added regression cases for schema-invalid success and failure JSON payloads
Validation: focused MCP tests 18 passed; full suite 9,535 passed, 19 skipped with 9,554 collected; Ruff passed; dependency audit found no known vulnerabilities.
AI disclosure: Posted on behalf of @mnriem by GitHub Copilot using GPT-5.6 Sol in autonomous mode; the code, tests, validation, and this review-round summary were AI-assisted.
Validate the child payload in strict mode. Pydantic's default lax validation accepts values such as 1 or "true" for a boolean feature, so malformed CLI output is silently normalized and returned as a success instead of producing invalid_success_payload; that also breaks the promised direct-payload contract. Pass strict=True here and add a coercible-type case to the invalid-payload matrix.
Add a case with non-UTF-8 bytes so the explicit invalid_utf8 adapter failure remains covered. The current negative matrix reaches empty, malformed JSON, schema-invalid, and mixed-output branches, but deleting the UnicodeDecodeError normalization would still leave it green, contrary to the repository's deterministic-behavior coverage requirement.
enabled strict Pydantic validation for both successful version payloads and structured CLI failure payloads, preventing coercion of malformed machine output
added regression coverage for coercible boolean values and non-UTF-8 subprocess output normalized to invalid_utf8
Validation: focused MCP tests 20 passed; full suite 9,537 passed, 19 skipped with 9,556 collected; Ruff passed.
AI disclosure: Posted on behalf of @mnriem by GitHub Copilot using GPT-5.6 Sol in autonomous mode; the code, tests, validation, and this review-round summary were AI-assisted.
Launch the child CLI with Python safe-path mode so a project-local package cannot shadow the installed MCP worker, with a real cwd-shadow regression test.
Assisted-by: GitHub Copilot (model: GPT-5.6 Sol, autonomous)
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Addressed the worker-shadowing finding in 5ae9c349:
launch the child CLI with Python safe-path mode (-P) so the MCP host working directory is not prepended to module lookup
added a real regression that changes into a project containing a shadow specify_cli.mcp_server._worker package and verifies the installed worker still runs
Validation: focused MCP tests 21 passed; full suite 9,538 passed, 19 skipped with 9,557 collected; Ruff passed.
AI disclosure: Posted on behalf of @mnriem by GitHub Copilot using GPT-5.6 Sol in autonomous mode; the code, tests, validation, and this review-round summary were AI-assisted.
This conversion drops the structured CLI error at the MCP boundary. MCP SDK 2.2 turns a raised ToolError into is_error=True with only str(exc) in text content (prefixed with Error executing tool ...), leaving structured_content empty. Clients therefore cannot read error.code, error.message, and error.details as the structured failure promised by the PR/docs without scraping JSON from free-form text. Return an error CallToolResult carrying both readable text and the payload in structured_content, and assert that wire shape in the stdio test.
Addressed the structured MCP error finding in 56ff5b30:
return explicit error CallToolResult values with readable text, isError: true, and the unchanged structured error.code, error.message, and error.details payload
updated in-memory coverage and the real stdio integration test to assert the wire-level structuredContent error shape
Validation: focused structured-error tests 6 passed; full suite 9,538 passed, 19 skipped with 9,557 collected; Ruff passed.
AI disclosure: Posted on behalf of @mnriem by GitHub Copilot using GPT-5.6 Sol in autonomous mode; the code, tests, validation, and this review-round summary were AI-assisted.
The reason will be displayed to describe this comment to others. Learn more.
Copilot review overview
🔵 Needs a closer look
The unbounded stdio integration test can stall CI indefinitely when the server stops responding.
Review effort: Balanced Findings: None
Previously missed (1)
In code that hasn't changed since last review
Add read deadline to prevent subprocess test hangs
tests/specify_cli/mcp_server/test_stdio.py:70
Bound this real subprocess protocol test. The session currently has no read deadline, so a regression that starts the child but stops it replying will hang the test job instead of producing a failure. An outer timeout also ensures cancellation unwinds the contexts and terminates the child.
Addressed the unbounded stdio integration test in d13c0350:
configured a 10-second MCP session read deadline
wrapped the complete subprocess handshake in a 30-second asyncio.timeout, so cancellation unwinds both async contexts and terminates the child
Validation: the bounded stdio integration test passed; Ruff passed. A full local run completed 9,512 non-PowerShell tests successfully, but 26 pre-existing PowerShell cases failed because the host pwsh runtime now crashes before script execution with System.IO.FileLoadException: The given assembly name was invalid; a direct pwsh -NoProfile health check reproduces the same runtime failure. The preceding full run on this branch passed all 9,557 collected tests before this test-only timeout change.
AI disclosure: Posted on behalf of @mnriem by GitHub Copilot using GPT-5.6 Sol in autonomous mode; the test change, validation, investigation, and this review-round summary were AI-assisted.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
specify mcpcommand using the official Python MCP SDKspecify_list_commands,specify_describe_command, andspecify_run_commandtool surface over stdio onlyversioncommand and executespecify version --jsonthrough an isolated child process using the running CLI's Python environmentScope
The supported inventory is deliberately explicit and contains only
version. Unsupported commands return anunavailable_commandtool error. This change does not expose HTTP/SSE transports, project discovery, artifact commands, mutations, installation/update/removal, workflows, confirmations, access tiers, or generalized timeout/cancellation infrastructure.The official
mcp>=2.2.0,<3.0.0SDK is a production dependency. Although the SDK brings HTTP/SSE-related transitive packages,specify mcpregisters and documents only stdio transport.Validation
uv sync --extra test— passed.venv/bin/python -m pytest tests/specify_cli/test_command_mcp.py tests/specify_cli/mcp_server -q— 22 passed.venv/bin/python -m pytest tests/specify_cli -q— 2,932 passed, 1 skipped.venv/bin/python -m pytest— 9,533 passed, 19 skipped, 62 warnings; 9,552 collected in 11m 06suvx ruff@0.15.0 check src tests— passeduvx --from pip-audit==2.10.0 pip-audit --disable-pip --require-hashes -r .github/security-audit-requirements.txt --progress-spinner off— no known vulnerabilitiesAI assistance
Implemented with GitHub Copilot using GPT-5.6 Sol in autonomous mode; code, tests, documentation, dependency updates, review, and validation were AI-assisted.