Skip to content

feat(mcp): remote instance (device) read tools - #7726

Open
andypalmi wants to merge 3 commits into
mainfrom
feat/mcp-tools-team-data-read
Open

feat(mcp): remote instance (device) read tools#7726
andypalmi wants to merge 3 commits into
mainfrom
feat/mcp-tools-team-data-read

Conversation

@andypalmi

@andypalmi andypalmi commented Jul 4, 2026

Copy link
Copy Markdown
Contributor

Summary

Phase 1 read-only MCP tools for the remote instance (device) resource, added to forge/ee/lib/mcp/tools/devices.js:

  • platform_get_remote_instance_audit_log - GET /devices/:deviceId/audit-log, takes a format: 'json' | 'csv' argument. json reads audit-log entries; csv exports the CSV via GET /devices/:deviceId/audit-log/export.
  • platform_list_team_provisioning_tokens - GET /teams/:teamId/devices/provisioning

Each tool describes the device resource, so all are filed with the existing device tools, following the one-file-per-resource convention. All tools are annotated readOnlyHint: true, destructiveHint: false.

platform_list_team_provisioning_tokens returns the summary view, which omits the token secret.

Scopes allow-listed in IMPLICIT_TOKEN_SCOPES['user:expert-mcp'] (forge/routes/auth/permissions.js):

  • device:audit-log
  • team:device:provisioning-token:list

Write, delete, and credential-issuing endpoints for this resource are out of scope for this PR.

Closes #7708

Consolidation notes

  • The remote HTTP-tokens and remote history tools that this PR originally carried are folded into the generalized platform_list_instance_http_tokens and platform_get_instance_history tools on feat(mcp): hosted instance read tools #7727. Each takes an instanceType: 'hosted' | 'remote' argument and so serves remote instances (devices) too, removing the need for remote-only variants here. The project:history scope and the remote HTTP-tokens scope move with those tools to feat(mcp): hosted instance read tools #7727.
  • Audit read and export are combined into a single platform_get_remote_instance_audit_log tool via a format: 'json' | 'csv' argument: json reads entries and csv exports the CSV through the /export route.

Test plan

  • eslint on changed files passes with no errors
  • mocha on changed files passes
  • CI

@codecov

codecov Bot commented Jul 4, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 76.27%. Comparing base (a8f760b) to head (3f10c03).

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #7726      +/-   ##
==========================================
+ Coverage   76.17%   76.27%   +0.10%     
==========================================
  Files         440      440              
  Lines       23604    23615      +11     
  Branches     6285     6286       +1     
==========================================
+ Hits        17981    18013      +32     
+ Misses       5623     5602      -21     
Flag Coverage Δ
backend 76.27% <100.00%> (+0.10%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@andypalmi
andypalmi force-pushed the feat/mcp-tools-team-data-read branch from 9ccc25a to 6a6f4cb Compare July 4, 2026 13:33
@andypalmi andypalmi linked an issue Jul 6, 2026 that may be closed by this pull request
@andypalmi
andypalmi force-pushed the feat/mcp-tools-shared-schemas branch from 8bfb22e to 9742987 Compare July 6, 2026 13:13
@andypalmi
andypalmi force-pushed the feat/mcp-tools-team-data-read branch from 6a6f4cb to 9d267f6 Compare July 6, 2026 16:39
@andypalmi
andypalmi force-pushed the feat/mcp-tools-team-data-read branch from 9d267f6 to 737394c Compare July 6, 2026 22:01
@andypalmi andypalmi changed the title feat(mcp): team data and package read tools feat(mcp): remote instance (device) read tools Jul 7, 2026
@andypalmi
andypalmi marked this pull request as draft July 30, 2026 08:21
@andypalmi
andypalmi force-pushed the feat/mcp-tools-shared-schemas branch from 103f9ae to 5773bdb Compare August 3, 2026 13:19
Add forge/ee/lib/mcp/schemas.js, a shared module of composable zod
fragments the platform read tools import instead of redefining entity-id
and pagination/search/sort/audit-log query fields in each tool file.

- entity-id params: teamId, applicationId, hostedInstanceId (UUID),
  remoteInstanceId, snapshotId
- query fragments composed per route by spreading only the params the
  backing finder honors: cursorParam/limitParam (basePagination),
  pageParam, searchQuery, sortParams, auditLogFilters
- appendQuery serialises a tool's supported params onto the request URL

The module lives one level above tools/ so the tool loader does not
register it as a tool module.

Closes #7669
@andypalmi
andypalmi force-pushed the feat/mcp-tools-shared-schemas branch from eae081f to e04360f Compare August 3, 2026 14:13
@andypalmi
andypalmi force-pushed the feat/mcp-tools-team-data-read branch from 4cc7f56 to 2e3e1d6 Compare August 3, 2026 15:32
@andypalmi
andypalmi requested a review from cstns August 3, 2026 15:47
@andypalmi
andypalmi marked this pull request as ready for review August 3, 2026 15:47
@andypalmi
andypalmi force-pushed the feat/mcp-tools-team-data-read branch from 2e3e1d6 to 312b18b Compare August 4, 2026 10:52
@andypalmi andypalmi self-assigned this Aug 4, 2026
Base automatically changed from feat/mcp-tools-shared-schemas to main August 5, 2026 08:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5.12-a Remote instance (device) read tools (phase 1)

2 participants