MCP design review: curate the agent surface, fix annotations, and build #491 Events on top #999
Open
opened 2026-10-03 08:52:05 +00:00 by kayg
·
5 comments
No Branch/Tag specified
dev
wip/rev2-money-ident
wip/restyle-notes
wip/previewcard-1098
wip/palette2-1123
wip/palette-1093
wip/onboard2-1141
wip/onboard-1141.aborted-early
wip/onboard-1141
wip/nlpchip-1127
wip/morph-1104
wip/merge-round-7c5
wip/merge-round-7c4
job/notifloop-1194
wip/merge-round-7c3
wip/merge-round-7c2
wip/merge-round-7c
wip/mchrome-1084
wip/mailghost2-1094
wip/mailghost-1094
wip/kbpreview2-1118
wip/kbpreview-1118
wip/kanban-1092
wip/importhang-1121
wip/hiderev-1153
wip/hide4-1153
wip/hide3-1153
wip/hide2-1153
wip/hide-1153
wip/editreg-1132
wip/editorrail3-1113
wip/editorrail2-1113
wip/editorrail-1113
wip/e2e-b2-1071
wip/e2e-b-1071
wip/draw4-1101
wip/draw3-1101
wip/draw2-1101
wip/draw-1101
wip/directory-1199-r
wip/directory-1199
wip/delete-1119
wip/collabrev-1197
wip/collabloss-1197
wip/cards2-1083
wip/cards-1083
wip/canvas-visual
wip/canvasvis2-976
wip/calhdr-1112
wip/calcards-1115
wip/browserfix
wip/blocks-1125
wip/allday-1107
wip/agenda-decks
wip/agenda-1086
wip/adv7c-1105
wip/txentry-1198
wip/trayicons2-1095
wip/trayicons-1095
job/onboard-1141
wip/sidebar3-1094
wip/rev2-webperf
job/collabloss-1197
job/hide-1153
job/perf-1124
job/perf2-1124
job/tocrail-1191
job/restyle-settings
wip/restyle-settings
job/segmented-1200
wip/notifloop-1194
job/tagperf-1186
wip/tagperf-1186
wip/segmented-1200
job/restyle-files
job/tagdnd-1187
job/merge30
job/cards-1179
wip/cards2-1179
wip/cards-1179
wip/tocrail-1191
wip/tagdnd-1187
wip/restyle-files
wip/perf-1124
wip/merge30j
job/restyle-notes
job/wizchoices-1140
job/adv-1202
wip/wizchoices-1140
wip/restyle-1190
job/moneyfmt-1180
job/txentry-1198
wip/moneyfmt2-1180
wip/moneyfmt-1180-r
wip/moneyfmt-1180
job/pillglass-1189
job/flags-1181
wip/flags-1181
job/restyle-1190
job/restyle-mailmoney
job/restyle-search
job/settingsreg-1195
job/wizard-1140
site/website
wip/wizardrev2-1140
wip/wizardrev-1140
wip/wizard5-1140
wip/wizard4-1140
wip/wizard3-1140
wip/wizard2-1140
wip/wizard-1140
wip/pillglass-1189
wip/settingsreg-1195
job/merge29
job/fu-1171
wip/merge29j
wip/fu-1171
job/fu-1166
job/directory-1199
job/proflog-1204
job/txresearch-1188
wip/fu-1166
job/merge28
job/search-1066
wip/search-1066
wip/merge28j
job/gateslot-1182
job/bulkimport-1157
job/mailnet-1160
wip/mailnetrev-1160
wip/mailnet-1160
wip/bulkrev-1157
wip/bulkimport-1157
job/startup-1161
wip/startup-1161
job/merge27
job/linkcards-1151
wip/linkcards3-1151
wip/linkcards2-1151
wip/linkcards-1151
job/traydate-1144
wip/traydate3-1144
wip/traydate2-1144
wip/traydate-1144
job/draw-1101
wip/merge27j
job/blockpill-1152
wip/blockpill3-1152
wip/blockpill2-1152
wip/blockpill-1152
job/minihover-1149
wip/minihover2-1149
wip/minihover-1149
job/merge25
wip/merge25-r
wip/merge25b
wip/merge25
job/inspector-1129
job/tags-1110
wip/inspector3-1129
wip/inspector2-1129
wip/inspector-1129
wip/tagsrev-1110
wip/tags2-1110
wip/tags-1110
job/dates-1148
wip/datesrev-1148
wip/dates2-1148
wip/dates-1148
job/licence-1145
wip/licence2-1145
wip/licence-1145
job/selfhost-1156
job/merge23
wip/merge23
job/tagfilter-1109
wip/tagfilter2-1109
wip/tagfilter-1109
job/kbd-1134
wip/kbd2-1134
wip/kbd-1134
job/palfoot-1137
wip/selfhost-1156
wip/palfoot2-1137
wip/palfoot-1137
job/toggle-1158
wip/toggle-1158
job/kbpreview-1118
job/docratchet-1155
job/perflint-1133
job/devtests-1159
wip/docratchet-1155
wip/devtests-1159
job/segv-1136
wip/toast-1142
wip/segv-1136
job/toast-1142
job/blockreload-1147
wip/blockreload-1147
job/font-1150
wip/font-1150
job/importui-1120
job/minimonth-1149
wip/importui-1120
wip/minimonth-1149
job/depcheck-1146
wip/perflint-1133
wip/depcheck-1146
job/calcards-1115
job/blocks-1125
job/plus-1128
job/shift-1138
wip/plus2-1128
wip/plus-1128
wip/shift-1138
job/moneyfid-1130
job/editorrail-1113
wip/moneyrev-1130
wip/moneyfid-1130
job/noext-851
wip/noext-851
wip/noext3-851
wip/noext2-851
job/week-1135
wip/week-1135
job/editreg-1132
job/smoke-1122
wip/smoke-1122
job/docs-1143
job/palette2-1123
job/calhdr-1112
job/nlpchip-1127
job/mailghost-1094
job/reconnect-1131
wip/reconnect-1131
job/trayicons-1095
job/delete-1119
job/importhang-1121
job/cards-1083
job/palette-1093
job/mchrome-1084
job/e2e-a-1071
job/canvas-visual
job/previewcard-1098
job/allday-1107
wip/e2e-a2-1071
wip/e2e-a-1071
job/e2e-b-1071
job/adv7c-1105
job/kanban-1092
job/agenda-1086
job/merge-round-7c
job/morph-1104
wip/surfaces-p2
job/merge-round-9
wip/merge-round-9
job/7cfix-small
wip/7cfix-small
job/mailui-1078
job/merge-round-8
wip/merge-round-8
wip/mailui-1078
job/mailround-1038
job/applemail-accept
wip/settitle-1068
wip/mailround2-1038
wip/mailround-1038
wip/e2e-7b
job/crash-1069
wip/crash-1069
job/searchlost-1066
wip/searchlost-1066
job/7b-reconcile
job/flake-1065
wip/flake-1065
wip/merge-round-7b7
wip/merge-round-7b6
wip/merge-round-7b5
wip/merge-round-7b4
wip/7b-reconcile
job/appupdate-1059
job/nfd-1044
wip/appupdate-1059
job/e2e-7b
job/loop-1062
wip/loop-1062
job/pdfprev-1045
job/invtoggle-1053
wip/pdfprev-1045
wip/nfd-1044
wip/invtoggle-1053
job/7bfix-e2e
job/mailstress-b
wip/7bfix-e2e
wip/mailstress-b
job/7bfix-adv
wip/7bfix-adv
job/mailstress-a
job/stack-1054
wip/stack-1054
wip/mailstress-a
job/mailstress-1038
wip/mailstress-1038
job/upload500-1051
wip/upload500-1051
job/share-1034
wip/share-1034
job/syncerr-1037
job/7bfix-photos
wip/7bfix-photos
job/paste-1036
job/setside-1039
wip/setside-1039
wip/paste-1036
job/lease-1042
wip/syncerr-1037
wip/lease-1042
job/7bfix-data
job/passkeybind-1043
wip/apprevoke-1041
job/invite-1035
wip/invite-1035
job/merge-round-7b2
wip/merge-round-7b2
job/mailproxy-486
job/apprevoke-1041
job/rebuild-1033
job/pillborder-1029
wip/pillborder-1029
wip/mailproxy-486
wip/applemail-486
job/headless-998
wip/headless-998
job/groups-1028
wip/groups-1028
job/rebuildwarn-1016
wip/rebuildwarn-1016
job/startup-1011
wip/startup-1011
job/monthpill-1009
job/bgthumb-1025
job/sharetitle-1012
wip/monthpill-1009
wip/bgthumb-1025
wip/sharetitle-1012
job/canvas-cards-977
wip/canvas-cards-977
job/canvas-pencil-978
job/canvas-sketch-990
wip/canvas-sketch-990
wip/canvas-pencil-978
job/canvas-files-989
wip/canvas-files-989
job/canvas-collab-991
wip/canvas-collab-991
job/weekscroll-1018
wip/weekscroll-1018
wip/canvas-core-976
job/canvas-core-976
job/round-drag
wip/round-drag
job/round-settings
job/browserfix
wip/oapi-974
job/oapi-974
job/hist2-integrate
job/mailhtml-726
wip/mailhtml-726
wip/hist2-integrate
job/moneyfu-984
job/drag-1015
wip/drag-1015
job/rename-1017
wip/rename-1017
job/hist2-api
wip/hist2-api
job/oneacct-1014
wip/oneacct-1014
wip/moneyfu-984
job/hist2-bench
job/hist2-restore
wip/hist2-bench
job/hist2-write
job/hotfix-724
wip/hotfix-724
wip/hist2-write
wip/hist2-restore
job/hist2-store
job/hist2-ui
wip/hist2-ui
wip/hist2-store
job/searchstarve-965
job/shutdown-963
wip/shutdown-963
wip/pubedit-981
job/pubedit-981
job/analytics-973
wip/searchstarve-965
job/authflash-850
job/weeklane-969
job/pvtitle-1004
job/hist-975
wip/authflash-850
job/voicepill-617
wip/pvtitle-1004
job/headring-1003
wip/weeklane-969
wip/voicepill-617
wip/headring-1003
wip/analytics-973
job/agentscope-980
wip/thumbsandbox-988
job/thumbsandbox-988
wip/hist-975
job/links-856
wip/links-856
job/davetag-966
wip/davetag-966
job/filesstorm-1000
job/hoverpad-725
wip/filesstorm-1000
job/ffmpegblas-993
job/merge-round-7a
wip/hoverpad-725
wip/ffmpegblas-993
job/nowdot-1002
wip/verify-7a
job/noteid-857
wip/nowdot-1002
wip/noteid-857
wip/merge-round-7a
wip/agentscope-980
job/imapedge
job/a11yfix2
wip/imapedge-941
wip/imapedge
wip/a11yfix2
job/notetask-986
job/logheading
wip/logheading-998
job/textthumb-652
job/photolive-987
wip/photolive-987
job/davactive-983
job/savefix-985
job/tabicons-607
wip/davactive-983
wip/tabicons-607
wip/notetask-986
wip/savefix-985
job/dirid-627
job/buildspeed-1007
wip/dirid-627
job/agenda-decks
job/perfguards-impl
job/undo-a11y
wip/undo-a11y
job/mailperf
job/wal-824
wip/settings-50
job/settings-50
job/notesfilter-606
wip/notesfilter-606
job/surfaces-p2
wip/wal-824
job/maillayouts
wip/mailperf
wip/maillayouts
job/taskmeta-659
job/money-ident
wip/money-ident
wip/taskmeta-659
job/errstates
wip/perfguards-impl
job/headings-881
wip/headings-881
wip/errstates
job/voice-619
job/gaps-827
job/notesperf
wip/notesperf
wip/voice-619
job/hddsql-549
job/perf-stream-668
wip/perf-stream-668
wip/deeplinks-fix
job/deeplinks-fix
job/authfix
job/docsfix-rust
wip/docsfix-rust
job/webperf
job/docsfix-web
job/datafix2
job/webdav-lock-476
job/copyfix
wip/copyfix
wip/webperf
job/focus-658
wip/protofix
job/mediafix
job/protofix
wip/mediafix
job/agentfix
job/hhmm-724
wip/agentfix
job/undo-722
job/reuse
wip/webdav-lock-476
wip/reuse
job/scopefix
job/datafix
wip/hhmm-724
wip/undo-722
job/surfaces-p1
wip/hddsql-549
job/voicememos-618
wip/datafix2
wip/surfaces-p1
job/fix-940
wip/fix-940
job/blaze-surfaces
wip/datafix
wip/blaze-surfaces
job/taskday-655
job/linknav-639
wip/linknav-639
wip/gaps-827
job/isolation-707
job/audiophotos-720
wip/audiophotos-720
job/advfind-664
wip/voicememos-618
wip/taskday-655
wip/isolation-707
wip/advfind-664
wip/scopefix
wip/focus-658
job/testgaps
wip/testgaps
job/overscroll-718
wip/authfix
job/deps
wip/overscroll-718
job/rev2-agentfix
job/rev2-money-ident
job/rev2-mailperf
wip/deps
job/hardening-728
wip/hardening-728
job/searchgen-832
wip/searchgen-832
job/photopw-849
job/mailsql-825
wip/photopw-849
job/sharefix
wip/sharefix
job/rev2-mailhtml-726
job/rev2-perfguards
job/copyval-723
job/lightglass-r2
wip/lightglass-r2
wip/docsfix-web
job/copy-audit
job/macinterop-staging-r2
job/design-sync
job/rev2-taskmeta-659
job/rev2-webperf
job/docs-audit
job/rev2-advfind-664
job/rev2-mailproxy-486
job/states-audit
job/rev2-datafix
job/design-drift
job/test-gaps
job/rev2-voicememos-618
job/rev2-mediafix
job/rev2-deps
job/rev2-datafix2
job/licence-audit
job/issue-hygiene
job/rev2-protofix
job/rev2-voice-619
job/rev2-isolation-707
job/rev2-surfaces-p1
job/deeplink-audit2
job/rev2-audiophotos-720
wip/test-gaps
job/rev2-overscroll-718
job/rev2-undo-722
wip/states-audit
job/rev2-dropmd-719
job/rev2-linknav-639
job/merge-7b-plan
wip/merge-7b-plan
job/rev2-taskday-655
wip/mailsql-825
job/rev2-webdav-lock-476
job/rev2-browserfix
wip/design-drift
job/rev2-hddsql-549
wip/deeplink-audit2
job/rev2-scopefix
job/rev2-authfix
job/rev2-hardening-728
job/rev2-wal-824
job/rev2-sharefix
job/calsidebar-638
job/chrome-audit
job/ioperf
wip/ioperf
wip/chrome-audit
wip/calsidebar-638
job/dropmd-719
wip/dropmd-719
job/ocr-build
wip/ocr-build
job/blaze-settings
wip/copyval-723
job/toastring-721
wip/toastring-721
job/deployfix-732
wip/deployfix-732
wip/blaze-settings
job/money-import-recheck
job/rev-a11y
job/perf-arch-db
job/rev-7b-data
wip/textthumb-652
wip/perf-arch-db
job/sec-protocols
job/sidehdr-660
job/rev-7b-security
job/research-surfaces
job/rev-design-gaps
job/rev-mcp-api
wip/sidehdr-660
job/perf-arch-memory
wip/sec-protocols
job/perf-arch-bundle
job/snapedge-714
wip/rev-mcp-api
job/sec-supplychain
wip/research-surfaces
job/perf-arch-sync
job/rev-consistency
job/perf-arch-server
wip/perf-arch-server
wip/perf-arch-memory
job/perf-arch-io
job/perf-arch-client
job/sec-fs
job/sec-mcp-scopes
job/sec-sharing
job/perf-guards
job/sec-browser
job/sec-admin-deploy
job/sec-auth
wip/snapedge-714
job/bgpicker-717
wip/perf-arch-bundle
wip/money-import-recheck
job/advsetup-654
wip/bgpicker-717
wip/advsetup-654
job/burst-709
job/kbdcaps-710
job/app-pw-chooser
wip/burst-709
wip/app-pw-chooser
job/imaptest-625
wip/kbdcaps-710
job/fix-499
wip/fix-499
job/perf-mut-667
job/calimg-589
job/perf-snap-666
wip/calimg-589
wip/perf-snap-666
wip/perf-mut-667
job/perf-cache-665
wip/perf-cache-665
job/voicefiles-620
wip/voicefiles-620
job/admin-burst-705
wip/admin-burst-705
job/voicememos-review
wip/voicememos-review
wip/ryw-653
job/ryw-653
job/writeonopen-661
job/instant-663
wip/writeonopen-661
job/money-import-review
wip/money-import-review
wip/importjs-610
review/integrations-407-round6
wip/integrations-review
job/dragghost-612
wip/dragghost-612
job/integrations
wip/integrations
job/decider-656
job/merge-round-6
job/perf-rerun
wip/merge-round-6
job/integrations-review-round5
job/selalign-576
wip/selalign-576
job/mcp-events-491
job/files-631
job/cal-e2e-569
wip/cal-e2e-569
job/reload-423
wip/reload-423
wip/mcp-events-491
wip/files-631
job/notesbridge-644
wip/notesbridge-644
job/editor-series
job/calcard-series
wip/calcard-series
job/mcp-events-review-491
wip/mcp-events-review
wip/editor-series
job/quirks-546
job/integrations-recheck
job/tocrail-636
wip/tocrail-636
wip/quirks-546
wip/reminders-643
job/reminders-643
wip/davscale-573
job/davscale-573
job/integrations-review
wip/ocr-eval-584
job/ocr-eval-584
job/esc-537
wip/esc-537
job/toastname-586
wip/toastname-586
job/submenu-579
wip/submenu-579
job/tasks-mode
wip/tasks-mode
job/agentdocs-630
job/dupwrite-634
wip/agentdocs-630
wip/dupwrite-634
job/lightglass-588
wip/lightglass-588
job/tabswitch-549
job/ghosttask-623
wip/ghosttask-623
job/toaststack-616
job/weekstate-609
job/mailsync-613
wip/mailsync-613
wip/weekstate-609
job/maildup-626
wip/tabswitch-549
wip/maildup-626
wip/toaststack-616
job/motion-611
wip/motion-611
job/tlstest-601
wip/tlstest-601
job/perf-495
job/floating-sheet
wip/floating-sheet
job/remdup-585
wip/remdup-585
job/fix-502
wip/fix-502
job/attachplay-622
job/perf-batch
wip/perf-batch-563
wip/perf-495
hotfix/mail-sync-diag
job/mail-m3
wip/mail-m3
job/attach-poof-603
job/calhover-608
job/editorbar-604
job/mentions-605
job/merge-round-4
job/allday-514
wip/merge-round-4
wip/allday-514
job/merge-round-4a
wip/merge-round-4a
job/sharestack-580
job/fix-501
wip/sharestack-580
wip/fix-501
job/perf-batch-563
job/apw-cache-review
wip/apw-cache-review
job/probe-520
wip/probe-520
job/mac-393
wip/mac-393
job/header-571
job/flake-513
wip/flake-513
job/docs-thumb-547
wip/header-571
job/webcal-572
wip/webcal-572
wip/shortcuts-542
job/shortcuts-542
wip/docs-thumb-547
job/caldav-stress
wip/caldav-stress
wip/sweep-478
job/apw-cache-512
wip/apw-cache-512
job/money-empty-540
wip/restart-505
wip/money-empty-540
wip/fix-510
job/restart-505
job/fix-503
job/perf-496
wip/perf-496
job/fix-498
wip/fix-498
job/info-inspector-465
wip/info-inspector-465
job/fix-510
job/fix-507
wip/fix-507
wip/fix-503
job/fix-493
job/money-kinds
wip/money-kinds
job/hygiene-548
job/merge-round-3
wip/fix-493
job/drag-snap-536
wip/merge-round-3
wip/merge-round-0930
wip/drag-snap-536
job/align-538
wip/align-538
job/bg-flash
wip/bg-flash
job/money-import
job/search-count-544
wip/search-count-544
wip/money-import
job/settings-key-541
wip/settings-key-541
job/toast-539
job/preview-421
wip/preview-421
wip/toast-539
job/tasks-500-531
job/title-plain-526
wip/title-plain-526
wip/tasks-500-531
job/notes-bridge
wip/parity-484
job/parity-484
job/files-slow
job/crash-525
wip/notes-bridge
wip/files-slow
wip/crash-525
job/kbd-motion-527
wip/bg-422
job/analytics-504
wip/analytics-504
wip/kbd-motion-527
job/upload-pill-523
wip/upload-pill-523
wip/tray-order
job/tray-order
wip/overflow-mid
wip/merge-round-2
job/perf-494
wip/perf-494
wip/mcp-fast-492
wip/motion-477
wip/asr-ab-489
wip/theme-variants-506
wip/overflow-511
wip/week-header-508
wip/attach-427
job/dav-delete-471
job/iso-435
wip/iso-435
wip/files-sel-keys
wip/dav-delete-471
job/align-253
job/siwc-490
wip/siwc-490
job/money-kinds-review
wip/align-253
wip/money-kinds-review
job/small-bugs-3
wip/overlay-title-487
wip/multiget-500
wip/hidden-420
wip/webcal-ui
wip/webcal-431
job/perf-367
job/location
wip/small-bugs-3
wip/location
wip/perf-367
wip/admin-deny-483
job/tag-unicode-473
wip/tag-unicode-473
job/blur-436
wip/photos-470
wip/blur-436
wip/small-bugs-4
wip/hunt-20260930
wip/settings-hdr-482
wip/chips-416
job/dedup-375
wip/dedup-375
job/doc-stack
wip/doc-stack
job/tokens-literals
wip/tokens-literals
job/jobs-leftovers
wip/send-fast
wip/paste-467
wip/money-numbers
job/money-plugin
wip/money-plugin
job/break-dav
wip/merge-batch
wip/crossday-469
wip/mac-verify
wip/mail-m2
wip/break-dav
wip/money-review2
job/money-md
job/modes-424
wip/money-md
wip/jobs-leftovers
job/agenda-413
wip/agenda-413
wip/modes-424
job/recog-417
wip/recog-417
wip/bounce-425
wip/ab-384-luna
job/webdav-perf
wip/webdav-perf
job/toast-ring
wip/toast-ring
job/money-review
wip/money-review
wip/micro-motion
wip/settings-card
wip/minical
job/notes-imap-428
job/least-priv
wip/ui-small-2
wip/flaky-426
wip/drag-end-418
job/jank
wip/jank
wip/least-priv
wip/docs-site
job/agenda
job/sec-batch
wip/sec-batch
wip/per-user-index
job/area-calendars
wip/area-calendars
job/parity
wip/parity
job/documents-research
wip/documents-research
job/test-infra
job/reminders-sync
wip/small-bugs-2
wip/reminders-sync
wip/gestures
job/google-oauth
wip/tags-merge
wip/tags
job/e2e-theme
wip/e2e-theme
job/icon-align
wip/test-infra
wip/select-align
wip/editor-385
job/voice
wip/webdav
job/webdav
job/app-pw-ui
job/editor-integrity
wip/editor-integrity
wip/voice
wip/quota
wip/cal-followups
wip/icon-align
job/composer-scale
wip/composer-scale
job/jobs-page
wip/jobs-page
job/hig-type
wip/hig-type
wip/app-pw-ui
job/motion-spring
job/mcp
wip/motion-spring
wip/mcp
job/small-bugs
wip/push-hosts
job/profile-sign
wip/touch-369
wip/profile-sign
job/mobile-focus
wip/mobile-focus
wip/ui-polish-354
wip/small-bugs
wip/dup-task
job/toast-polish
job/app-pw-scopes
wip/toast-polish
wip/app-pw-scopes
wip/cli-agent
wip/selection-pills
job/preview-attach
wip/preview-attach
job/dav-proppatch
wip/dav-proppatch
wip/cal-switcher
job/atomic-race
wip/atomic-race
job/photos-shared
wip/photos-shared
wip/cal-grid
wip/note-rewrite
wip/search-rebuild
job/mail-m1
job/paperless-import
wip/paperless-import
wip/mail-m1
wip/hidden-activity
wip/search-d
wip/pricing-research
wip/cursors
wip/auto-scheme
job/single-pills
wip/single-pills
wip/xuser-matrix
wip/money-format
wip/app-pw-setup
wip/purge-dos
wip/vault-health
wip/caldav-apple
wip/xuser-audit
wip/e2e-green
wip/tabbar
wip/adv-harness
wip/maple-mono
job/search-fix
wip/search-fix
wip/search-perf-c
job/adv-harness
wip/sidebar-headers
job/glass
wip/temp-index
job/polish
wip/polish
wip/file-protocols
wip/money-research
wip/glass
wip/voice-models
wip/collab-redo
job/voice-research
wip/hunt-20260928
wip/notes-actions-research
wip/search-pad
wip/search-perf
wip/search-sticky
wip/editor-undo
wip/chrome-rules
wip/motion
wip/appearance-research
wip/appearance
wip/audit-bugs
wip/cal-glass
wip/block-actions
wip/authz-order
wip/event-stripes
wip/chrome-sidebar
wip/auth-flaky
wip/robust-2
wip/gate-fix
wip/menu-blur
wip/import-calternaljs
wip/tray-fix
job/import-calternaljs
wip/index-order
wip/audit-fixes
wip/search-chevrons
research/mail
wip/phone-chrome
wip/dedup-break
wip/csp
wip/ui-audit
wip/select-toast
wip/perf
wip/flat-layout
wip/fonts
wip/event-tint
wip/sync-converge
wip/data-split
wip/glass-audit
wip/robustness
wip/sync-chaos
wip/search-thumbs
wip/fuzz
wip/menu-icons
wip/search-pill
wip/sync-changing
wip/heading-links
wip/date-formats
wip/a11y
wip/break-editor
wip/e2e-fix
wip/settings-sections
wip/sync-root-guard
wip/search-palette
wip/share-edit
job/toasts
wip/toasts
wip/cont-analytics
wip/authz-review
wip/popovers
wip/overlay-glass
wip/change-feed
wip/editor-modes
wip/composer-align
wip/cont-agenda
wip/agenda-merge
job/agent-conventions
wip/agent-conventions
wip/backend-misc
job/route-audit
wip/route-audit
wip/ui-batch
wip/heif-hardening
wip/grid-resize
wip/ask-page
wip/webmcp
job/deeplink-audit
wip/deeplinks
wip/shortcuts
wip/cont-tz-days
main
No results found.
Labels
Clear labels
No items
No labels
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
kayg/calternal#999
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
A design review of the calternal MCP server, checked against the MCP and agent-tool design guidance and the draft MCP Events extension that ChatGPT now supports. Live probe on 2026-10-03 against calternal.cloud (
system_infocommitc4a61e8cf) using a full-access MCP App Password, pluscrates/calternal-server/src/mcp.rsandcontracts/actions.jsonondev.The plumbing is good: one registry, the same route guards for every adapter, bounded dispatch, ETags, per-surface switches, App Password scopes and Home prefixes, and a durable per-User change feed. The problem is the design choice above the plumbing. #484 reads "parity" as one MCP tool per HTTP route. Every guide below says not to do that, and most of the open MCP issues (#817, #818, #821, #833, #836, #515) are symptoms of it. This issue does not repeat those. It covers the design calls they do not make, and how #491 (MCP Events) should be built on top of them.
Findings
1. The tool surface is a REST mirror (high)
tools/listfor a data-scope App Password returns 290 tools: 276 generatedcalternal_api_*plus 14 legacycalternal_*. Admin tools are filtered. 39 admin tools would also be listed for an admin credential.calendar_events,calendar_items,calendar_range,by_day,daily,calternal_todayandnotes_journal_dayjust to answer "what did I do today?".Proposal: keep #484 parity for API and CLI. For MCP and WebMCP, define parity as "reachable", not "one tool per route":
find(kinds filter, limit, cursor), onegetby any calternal ID, event create/update/delete, mail list/read/mark, files list/read, money summary and add transaction, photo search.calternal_actions_search(query)returns matching registry actions with their schemas, andcalternal_actions_call(id, args)runs one through the same middleware. The MCP client best-practices page describes exactly this search-tools pattern for large catalogues.2. Tools that should never be on an agent surface (high)
These are in
tools/listtoday for my MCP App Password:assert_start/finish,add_start,remove_start/finish(WebAuthn, which an agent cannot complete),oidc_link_start/reauth_start/unlink,recovery_key,revoke_all,revoke_session,sign_out,cli_logout,create_app_password,create_app_password_profiles,download_app_password_profile,save_credential/remove_credential,rename_passkey,update_profile. An agent minting App Passwords or reading a recovery key is credential persistence, even if the route currently denies it.public_*,edit_read/edit_session/edit_write,entries,info,linked_note,public_linked_notes,calendar_public_feed. These are for anonymous visitors holding a slug, not for the owner's agent.files_create_upload/head/patch/terminate,photos_create_upload(base64 bodies),serve,public_thumb,appearance_unsplash_thumbnail, allvideo_hls_*andvideo_source_by_item, and SSE wrappers (events,change_wakeups,notes_events,my_job_events,stream_turn). These return rawevent: ...\ndata: ...text inside apoll_mswindow.record_search_opened,preferences_mode_order_*,appearance_*,files_set_pins.Also, the server instructions say "App Passwords cannot manage accounts or administration", yet all 29
account-scope tools are listed to App Password sessions. The model is told one thing and shown another (related #774, #836 item 3).Fix: add a
surfacesexclusion by category in the registry (auth ceremony, guest, transport, UI telemetry), so new routes in those families are off MCP and WebMCP by default. List them indocs/parity-exceptions.jsonwith the reason.3. Annotations are derived from the HTTP method (high)
generated_tool_definitionssets onlyread_onlyanddestructive, and inactions.jsonthose are exactlymethod == GET. Result:destructiveHint: true, includingnotes_journal_create_log,create_note,tasks_create,notes_composer_parse,parse,preview_rename,notifications_preview_block_reminderandmail_test_connection. Several of these are pure functions (#754).calternal_mail_reader, mostly reads, is hard-codedread_only_hint = false, destructive_hint = true. So iscalternal_calendar.idempotentHint,openWorldHintandtitleare never set. Spec defaults then claim every write is non-idempotent and every tool is open-world.Effect: hosts that gate on these hints (ChatGPT, Claude) prompt on nearly everything. Users get confirmation fatigue and click "always allow", and then the real destructive tools (
empty_trash,revoke_all,*_delete_*) lose their protection. The MCP blog post on annotations treats them as risk vocabulary for exactly this kind of host policy.Fix: a reviewed, checked-in policy table per action with all four hints plus
title, and a test thattools/listmatches it.destructive: false.PUTwithIf-Matchisidempotent: true.openWorld: trueonly where calternal talks to the outside: mail sync/send/test, calendar subscription fetch, bookmark clip fetch, Unsplash.mail_reader,calendar) so the read half can bereadOnlyHint: true.4. Names and descriptions are written for Rust developers, not models (medium)
#821 covers vague names. In addition:
appearance_put: "Box nested futures so debug workers do not carry the whole Files chain (#422)".appearance_get: "Migrate legacy background files before reading saved IDs...".change_head: "A rescan uses this high-water mark before it lists the Home...".update_body: "OpenAPI declares the revision header for every adapter (#484, DESIGN §9)". Describe the tool from the caller's side, and keep#nnn/§nnout of model-facing text.calternal_api_spends 14 characters. With a client prefix such asmcp__Calternal__,calternal_api_notifications_preview_block_reminder(50 chars) goes past the common 64-character limit, and Aside had to truncate it to..._preview_blo_23e9f90e. Dropapi_and usecalternal_<noun>_<verb>.5. Duplicate tools for the same job (medium)
These pairs are listed side by side, often with different argument names:
calternal_create_note/calternal_api_create_notecalternal_create_task/calternal_api_tasks_createcalternal_tick_task/calternal_api_tickcalternal_search/calternal_api_searchcalternal_open/calternal_api_get_notecalternal_create_log/calternal_api_notes_journal_create_logcalternal_duplicate_item/calternal_api_calendar_duplicate_itemcalternal_list_files/calternal_api_listcalternal_get_files_preferences/calternal_api_files_get_preferences(same forset_)#817 covers their contracts drifting apart. The design point is that only one of each pair should be in
tools/list. Keep aliases callable for compatibility, but do not advertise them.6. Schemas leak HTTP structure (medium)
{path, query, headers, body}groups. The model has to know thatheaders.If-Matchcarries a revision, that Tus needsTus-Resumable: 1.0.0, and so on. Flatten to semantic arguments (id,revision,title) and map them to HTTP in the adapter.$ref: #/$defs/...(CalendarAction,MailReaderAction,DuplicateItemKind). In my client the allowed values were not visible to the model.calternal_calendar(action: "list")failed with "must be equal to one of the allowed values" and did not say which values. Inline the enums and name the values in the description.7. Responses are not shaped for a context window (medium)
#836 covers structured output. In addition:
calternal_search("meeting")returned 41 results with nolimit,kindor cursor input. Mail and Files hits havescore: nulland come before the scored Log hits. Promotional mail ranks first. IDs expose internal storage (users/<uuid>/Notes/...#^...).hrefis relative.calendar_rangereturns every category as an empty array for empty days.resource_link(see also #760).limitwith a cursor on every list,kindsfilters,response_format: concise | detailed(Anthropic's recommendation), absolute deep links (https://calternal.cloud/d/2026-10-03#^...), stable public IDs, and resource links for files and notes.8. Errors do not help the model recover (low, mostly covered)
Covered by #818 and #836: a 404 becomes JSON-RPC
-32602 "The API route returned HTTP 404"instead of a tool result withisError: true.One addition:
calternal_open("does-not-exist")says only "Invalid Note ID". It should give the expected form (path:Notes/...) and name the tool that produces IDs.9. Remote sign-in discovery blocks ChatGPT and Claude connectors (high for #491)
POST /mcpwithout credentials returns401 {"code":"unauthenticated"}with noWWW-Authenticateheader./.well-known/oauth-protected-resourcereturns the SPA HTML with a 200 instead of RFC 9728 metadata or a 404. Hosted connectors cannot discover OAuth, so today only clients that accept a pasted bearer token work. #836 item 4 tracks this. It is a hard prerequisite for #491, because ChatGPT plugins need it before events matter.10. Server instructions are one inaccurate sentence (medium)
get_infosays the tools are "thin adapters over the calternal HTTP API", which is the problem from finding 1. The instructions should give the model:^blockID, Task, Event, Note IDs, and revisions/ETags.MCP Events (#491): design notes
#491's delivery and security list matches the OpenAI guide well: webhook only, Standard Webhooks signing, challenge verification, SSRF guard, 256 KiB limit, and stop on 410/413. Points it misses or gets wrong:
mail.receivedcomes from IMAP sync.task.due/overdue,calendar.event_starting,reminder.firedandmoney.bill_duecome from the scheduler.share.*comes from another User. Keep a small, hand-reviewed event catalogue with reviewedpayloadSchemas, fed by (a) the change feed and (b) the scheduler. Generating events would also inherit findings 3 and 4./files/changesalready has a per-User monotonic cursor,change_headand a floor. That gives realcursorvalues and honesttruncated: truewhen a cursor falls below the floor. Most servers can only returncursor: null. The feed is file-level (write Notes/20261003-dailynote.md), so it needs a domain projection (log.created,task.completed). MakeeventIdstable across retries, for example<feed cursor>:<event>:<block id>, or the mail UIDVALIDITY:UID.mail.receivedcarries{account_id, message_id, thread_id, from, subject, received_at, url}and the agent reads the body with the mail read tool. This only works well once the curated read tools from finding 1 exist. Never put instructions in payloads (#746).log.created, add a tag" re-fires forever. Putactor: {kind, app_password_id}in every payload, and add a default-on subscription filterexclude_own_writes.create_log,tasks_createandmoney_create_transactiontake no idempotency key. Add an optionalidempotency_key(agents can pass theeventId). Related #814.terminated, so stop delivery and answer the next refresh with-32012 Forbidden. Grant a finite TTL (days, notnull) and store subscriptions in SQLite so they survive restarts, as the guide requires.MCP_PROTOCOLSalready lists2026-07-28, butget_infoenables only tools. Confirm that rmcp answersserver/discoverwithcapabilities.eventsand routesevents/*on the same authenticated endpoint.mail.received,log.created,task.due,calendar.event_starting,file.added(folder filter). Money and share events come after the payloads and filters prove out. Filters stay simple key-value, as the draft says: no query language.Suggested order
actions_search/actions_call(1), and hiding duplicate tools (5). Measuretools/listtokens before and after (#515).Sources
Related: #484, #491, #515, #746, #754, #760, #774, #789, #814, #817, #818, #821, #833, #836
Started independent read-only re-critique for #999 on the existing dev checkout. HEAD/base and origin/dev:
f06679b11c. Reviewed 7a head:516faaa698. No checkout, merge, code change, commit, production probe or runtime certification is planned. Source counts already distinguish 290 tools on dev from 295 on 7a; checking primary specifications and all cited issue threads before the final reply.Source findings for the re-critique (not runtime certification):
f06679b11and 7a516faaa69, the non-admin generated definitions contain 153 and 156 explicit destructive hints. Five legacy tools explicitly set the hint; nine omit annotations. The non-admin totals are 158/161 explicit or 167/170 with MCP defaults. The issue's 189 is not reproduced at these heads.The final reply will classify every original finding, separate owner decisions from defects, and propose implementation slices without changing code.
Independent re-critique of #999
Keep the shared registry and route authorization. Fix discovery, annotations, contracts and Events delivery first. A smaller default catalogue is a product choice to test, not a conclusion proved by the tool count. Several proposed exclusions would remove capabilities the owner explicitly required in #484.
This is a read-only review on 2026-10-03. I fetched origin once and inspected immutable snapshots:
origin/dev:f06679b11cde29cc0b7120fdab5f721389caf695(also checkout HEAD).origin/job/merge-round-7a:516faaa698570bdb468626cf6cd75d9c81b33ac2.Evidence below uses dev file lines unless marked 7a. Both heads have the same underlying tool-contract defects discussed below; 7a also has Events and agent setup documents. I read the bodies and all comments of #484, #491, #515, #754, #774, #817, #818, #821, #833, #836 and #472. Work reported on other job branches is not assumed to be merged. For example, #754/#818/#821/#836 comments report fixes that are absent from these snapshots. Coordinate with those jobs rather than repeat their work.
Document correction: DESIGN §9 is Notes and the editor, not the parity decision. #484 states the parity rule; DESIGN §41 states the thin-adapter rule. §55 sets Events decisions. §58 exists on 7a, but not this dev head. There is no §59 in either reviewed DESIGN file. §60's one-event-path rule applies to Canvas collaboration writes; it must not be interpreted as a ban on a webhook delivery queue.
Reproduced counts
I reconstructed the generated definitions from
contracts/actions.jsonusing the fields emitted bymcp.rs:338. This is a deterministic source measurement, not a captured livetools/listresponse. JSON is compact UTF-8. Tokens use the repository benchmark's pinnedtiktoken==0.14.0. The local reproduction isartifacts/mcp-recritique-999/counts.py.o200k_basetokenscl100k_basetokensThe roughly 136 KB claim matches dev definitions without annotations. The actual reconstructed annotated array is 152 KB and 34,127
o200k_basetokens, before legacy definitions and the result envelope. The issue's 189 destructive tools is not reproducible at either reviewed head. All generated tools, including admin, have 177/180 explicit destructive hints. Five legacy tools explicitly set them and nine omit annotations; all fourteen legacy tools have effectivereadOnlyHint=falseanddestructiveHint=trueunder the defaults. This includes the read-only legacy Search, Open, Today, Files list and Files preference read tools.Findings 1–10
1. REST mirror — CONFIRMED; proposed replacement — PARTLY
scripts/action_registry.py:151advertises every supported non-onboarding route on all three generated adapters.mcp.rs:338maps it to tools;mcp.rs:1198filters only admin tools and ignores discovery cursors. The size and overlapping vocabulary are real.The claim that the whole catalogue necessarily enters model context before the first message is client-dependent. The official MCP client guidance describes host-side discovery: fetch the tools normally, then load selected definitions into model context. It does not require every server to replace its catalogue with a generic call tool. Server-side
actions_searchis an optional compatibility strategy, not that exact documented mechanism.The proposed 20–30 tools omit Contacts, Analytics, sharing and Collaborate, versions and restore, transfers/import/export, jobs, Connected Accounts, App Passwords, behavioural settings and Canvas element/export actions. Search/get cannot replace those writes. #484 explicitly includes these capabilities. Hiding them behind a dispatcher could preserve functional reachability only if discovery and execution work in the actual supported clients and the parity gate proves each action. A schema that accepts arbitrary
argsalso loses per-action validation and clear host confirmation policy.Recommendation: keep the complete canonical catalogue available to authorized clients; filter grants, remove redundant advertising, improve descriptions and page deterministically. Test an optional curated profile against full and host-deferred profiles. Use task success, missed capabilities, wrong writes, repair calls, total tokens and latency. Include a weaker client. Anthropic's guidance supports workflow tools and evaluation, but does not establish a universal optimum of 20–30 tools. Keep workflow wrappers generated from shared mappings; do not add separate writers.
2. Tools that should never be exposed — PARTLY
The 29 account labels and irrelevant transport/ceremony entries are confirmed. Examples:
contracts/actions.json:3474(create_app_password),:3405(profile download),:15801(public info),:16108(public entries),:15754(Tab order). But listing a tool does not prove the credential can invoke it.MCP dispatch retains the original credential (
mcp.rs:216); inner middleware checks it again and App Password context carries only data scope (wire.rs:2651).calternal-auth/src/api.rs:300checks account/admin authority; creating an App Password also requires a fresh assertion (:1441). The public profile download is a separate bearer-capability flow explicitly bypassing normal session extraction (wire.rs:2555vicinity), so a blanket “all account routes deny” statement is also wrong. Its token is consumed once, not a normal account read.Separate these cases:
Recommendation: reviewed per-action surface intent plus required scopes/freshness and an equivalent capability where relevant. Reuse
docs/parity-exceptions.json; do not use a broad path/category deny that silently exempts future User actions. #774 demonstrates why labels must describe actual guards. Discovery filtering is useful but cannot replace the guards.3. Method-derived annotations — CONFIRMED; details and fix — PARTLY
The generator uses GET/HEAD plus the ZIP-download POST exception, not exactly GET (
action_registry.py:146). Generated MCP emits only read/destructive hints (mcp.rs:352). Pure parsers are wrongly classified atcontracts/actions.json:12096and:13428; route read-access classification repeats this problem (wire.rs:2371). This is #754, not only a confirmation nuisance.calternal_mail_readerexplicitly has both false/true hints (mcp.rs:645).calternal_calendarhas no annotations (:1056), which produces conservative defaults; it is not hard-coded the same way. Read-only legacy tools also lack read-only annotations, which the critique missed. Confirmation fatigue is plausible, but no host confirmation rate or User behaviour was measured here.Use reviewed metadata in the common contract. The current MCP annotation schema defines destructive as possibly destructive updates; false means additive updates. Idempotent means repeating the same arguments adds no further effect. Both hints matter only when read-only is false. Hints are not authorization. Thus:
If-Matchprevents stale overwrites; it does not prove replay safety for audit records, versions, notices or jobs. Check effects per action. Keep replay policy separate from the hint.openWorldHintdescribes an open domain of entities, not whether a network socket exists. Bounded Connected Account reads can be closed-world; arbitrary URL fetch and mail to arbitrary recipients are open-world. OpenAI's current tool guidance makes this distinction.titleis useful display metadata, not a fifth risk dimension.Keep unknown actions conservative, and fail review for missing declarations. Pure previews must be allowed to read-only credentials through the route policy too. Split mixed tools only when the canonical tools retain every operation and old calls retain compatibility.
4. Names/descriptions — CONFIRMED; blanket rename — PARTLY
The quoted internal comments are in the registry and are copied directly into MCP descriptions:
appearance_put,appearance_get,change_head,update_body. Use the existingcontracts/action-overrides.jsonmechanism and caller-facing route summaries. Keep useful invariants such as revision requirements; do not merely delete technical terms or references without replacing the guidance.The longest name is 50 characters.
calternal_api_is 13, not 14;mcp__Calternal__is 15. Together they reach 65, so the cited 64-character client limit remains plausible. MCP itself recommends up to 128 characters, so this is a client interoperability constraint, not a protocol violation. Budget names for supported hosts and preserve aliases. A globalapi_deletion does not solve ambiguity and creates collisions with legacy names. #821 already has a canonical-name/alias job in progress.5. Duplicate tools — CONFIRMED; hide all pairs — PARTLY
Legacy and generated names are registered together (
mcp.rs:90). All listed pairs are present. They are often overlapping capabilities, not interchangeable aliases: one-entry Log versus batch, Home path versus item ID, different search fields, and browser navigation versus Note reading. #817's thread also records an attempted compatibility break when browser Open and Today were renamed.Choose a canonical data contract, preserve old argument shapes in explicit wrappers, and stop advertising redundant aliases only after supported-client tests. Browser navigation remains a distinct browser capability. “Callable but not advertised” must be tested: hosts can refuse tools absent from their imported catalogue. Do not assume that strategy preserves every existing client.
6. HTTP-shaped inputs and enum references — CONFIRMED; protocol defect claim — PARTLY
The grouped inputs come from
action_registry.py:106; legacy enums come frommcp.rs:368,:458,:514. The generated resolver already inlines local references (action_registry.py:69), while schemars emits the legacy references.$ref/$defsare valid JSON Schema, so the reported client losing enums is an interoperability failure, not invalid MCP schema.Flatten selected common workflows through shared, declared mappings. Preserve required revisions, upload offsets, content types and distinction between absent and null. Keep the raw canonical mapping for expert clients. Inline legacy enum values where this helps affected clients; explain each action and return a bounded allowed-values list on enum errors. Coordinate with #818 for field paths and #833 for schema correctness before cosmetic flattening.
7. Context-sized responses — PARTLY
Legacy Search accepts only
q(mcp.rs:362,:638). The API and generated action already accept a provider limit of 1–200, default 20 (main.rs:170,:705). They do not apply a global result cap: providers are concatenated in stable registry order (main.rs:1020), so 41 results and unscored hits before scored hits are plausible. “Promotional mail ranks first” and that exact result count are historical production observations, not reproduced on either head. Scores from different providers are not necessarily comparable; do not fix this by sorting nulls alone.Binary output is encoded as a base64 string in a text JSON envelope (
actions.rs:201,mcp.rs:107), confirmed. Empty category arrays are harmless overhead, not the same severity as unreachable later pages. Keep stable response shapes unless measurements justify a concise alternative.Recommendation: deterministic bounded pages where continuation makes sense; stable IDs, revision, continuation and partial-result state must survive concise output. Search needs an explicit global budget and kind semantics without starving providers; changing its ranking belongs in Search. A limit on every list is not necessary for a fixed small enum. Use configured Instance-origin absolute deep links, not a hard-coded deployment hostname. §33 IDs must survive rename. Images can use image content; large Files need an authenticated fetch path behind resource links. A
resource_linkalone does not implement authorization, transfer or a client read method. Add structured results alongside legacy text, with version-appropriate schemas. MCP tool-result guidance defines these content types and the text compatibility path. Concise/detailed is optional and should be evaluated, as Anthropic recommends.8. Errors — CONFIRMED; proposed Note ID example — WRONG
mcp.rs:321maps HTTP 4xx to invalid-params and 5xx to internal RPC errors. Domain failure should be a failed tool result with safe typed status/code, repair guidance and retryability. Malformed RPC/tool schemas remain protocol/input errors. Include revision conflict details without reflecting secrets, raw upstream HTML or Home payloads. #818 and #836 already own these slices.calternal_openusesUuid::parse_str(mcp.rs:786), sopath:Notes/...would still fail. Its help must name a stable Note UUID and the read/search action that returns that UUID. Search hit IDs are not automatically valid Note IDs. Browsercalternal_opencurrently takeshrefand navigates (tools.ts:156); it needs separate compatibility handling.9. Remote sign-in discovery — CONFIRMED; universal Events prerequisite — WRONG
I made two unauthenticated requests to STAGING only,
dev.calternal.com. POST/mcpreturned 401 JSON withoutWWW-Authenticate; GET/.well-known/oauth-protected-resourcereturned 200 HTML. No credentials were loaded. No production request was made. Source agrees:mcp.rs:1283returns the ordinary unauthenticated response; neither head has OAuth resource metadata routes. The DAV Basic challenge is unrelated.This blocks normal OAuth-discovered connection to private data. The MCP authorization specification requires protected-resource metadata and discovery challenges for that authorization flow. Metadata alone is insufficient: authorization service, PKCE, audience-bound tokens, scopes, consent, expiry and revocation must all work. An upstream OIDC sign-in provider is not automatically an MCP authorization server.
OAuth is a prerequisite for the targeted hosted authorization flow, not for Events as a protocol. A bearer client can subscribe and receive a signed webhook. #491's sender can be tested locally independently; hosted-client end-to-end acceptance should explicitly depend on #836. Do not delay every Events correctness fix until OAuth or curation is finished.
10. Server instructions — PARTLY
mcp.rs:1229contains the quoted short instructions. The account prohibition is correct for App Passwords; their discovery is misleading. It must distinguish authorized Installation sessions rather than promise account tools work for every bearer credential. “Thin adapter” matches DESIGN §41 and is not itself an inaccurate design.Add a concise vocabulary/identity/time-zone/revision primer, common first reads, partial-result rules and the untrusted-content boundary. 7a already has the public guide and Skill under §58 (
agent_docs.rs:32,agent_docs/skill_intro.md); extend those shared materials instead of writing a conflicting second manual. The Skill is not automatically loaded by MCP clients. Neither guide text nor an annotation makes an embedded instruction safe.What the critique missed
Read-only semantics are broken in the other direction too. Both snapshots' Daily GET creates and indexes a missing Daily note and updates nearby navigation (
crates/plugins/notes/src/lib.rs:3855). Its generated hint is read-only. The profile-download GET consumes a one-use credential token (contracts/actions.json:3405, quoted handler contract). Reviewing POST creates alone misses these state changes. #833's later thread reports the explicit Daily create/read split on another branch; require it in the combined round. This is source evidence, not a newly reproduced runtime exploit.The Note schema collision is an actual capability failure. Note and Task property handlers publish
PropertiesPatchwith different fields (notes/src/lib.rs:3621,tasks_api.rs:336,contracts/openapi.json:22031). Both snapshots still point Note edits at the colliding component. Agent-friendly names cannot fix a schema that describes the wrong write. Complete #833 before declaring semantic parity.Credential outputs require separate treatment. App Password creation and profile download return credential material; recovery issues a key. A scoped agent must not acquire account authority from text, and a normal tool-result envelope must not send newly minted credentials into model history or logs. Use a protected User completion/delivery channel if those workflows remain available. Recovery and profile download are not ordinary read tools. Keep route freshness and authority intact; curation is not a security boundary.
Prompt injection is a cross-surface data boundary. Note bodies, Mail subjects/bodies, filenames, snippets, linked content, public content and webhook fields can contain hostile instructions. Generated results currently become plain
ContentBlock::text(mcp.rs:107), without a provenance/data envelope. WebMCP'suntrustedContentHint(generated.ts:85) is only a hint. Use fixed server-owned metadata and nested untrusted data, bounded excerpts and safe error details. Validate mutations against granted authority and actual User intent; never let retrieved text select a new recipient, callback, credential scope or tool policy. Provenance labels reduce confusion but cannot guarantee prevention. #774's thread reports relevant envelope work on a separate branch.Cross-User classification is not runtime isolation proof. #472 is closed after the offline gate and live ownership checks; it did not report twenty exploitable routes. Its final thread retains unseeded fixture gaps. Current
xuser_matrix.py:282binds generated entries to classified routes, but classification does not exercise every MCP or WebMCP call. Replay A's real identities as B through legacy and canonical adapters; test admin denial, Share revocation, restricted Home/Plugin grants, account changes and cached tool lists. Derived data and event payloads need the same ownership proof. A shared cache must never key only on Role, and pagination cursors must not mix credentials or catalogue revisions.Tool-list performance is not per-call performance. Schema construction is already cached in a
OnceLock(mcp.rs:88).list_toolsclones definitions and searches the registry for each tool. Dispatch bounds calls at 16, request JSON at 128 KiB and responses at 1 MiB (mcp.rs:49–55). A base64 tool cannot use its nominal 1 MiB body allowance within a 128 KiB JSON request; a high-level transfer must publish the effective chunk bound. Oversized successful output can fail after a write, so do not treat a generic transport error as permission to repeat the write. Cancellation also needs a committed-versus-unknown outcome policy.The #515 baseline has eight tools/654 tokens and local warm
tools/listp95 21.051 ms (docs/perf/mcp-baseline.json:28,:229). Today's generated non-admin array alone is 34,127 tokens, about 52 times that token count; the payloads are different, so this is not a 52-times latency claim. No current authenticated latency, CPU or RSS measurement was made. Measure cold/warm discovery, scoped authentication and ordinary tool calls separately; identify double credential verification cost, serialization cost and SSE permit occupancy before optimizing. Curation alone cannot establish the server latency target.WebMCP is a browser surface, not remote MCP with a cookie.
tools.ts:141registers page callbacks and aborts their registration on teardown. Generated actions use the browser API client, confirmation andwithStepUp(generated.ts:78–104). An MCP App Password cannot use that browser ceremony; an account-scoped signed-in browser can. A callback AbortSignal currently controls registration and is not forwarded to the request transport, so teardown does not prove an in-flight write was cancelled. Preserve surface gates across confirmation and step-up, distinguish navigation from content reads, and test sign-out/User switch, cancellation, keyboard/touch confirmation and the current browser API. The WebMCP report is a Community Group report, not a W3C Standard. Keep native signature/cancellation tests against the actual supported browser.MCP Events re-review, against 7a as well as dev
Registry versus producers: PARTLY. DESIGN §55 explicitly requires event declarations in the shared action registry. Rejecting that would reverse an owner decision. 7a uses a reviewed
contracts/action-events.json, generated onto actions, then deduplicated bycalternal-api/src/events.rs:103. It does not infer event names from HTTP verbs. Keep this catalogue and separate runtime producers: background sync, deadlines and shared changes emit through the trusted producer bus (calternal-plugin/src/mcp_events.rs:1) and source workers. A declaration's action association does not mean that action is the only producer. Add validation that duplicate event names have identical schemas and that each advertised event has a live source.Durable feed/cursors: PARTLY. 7a already reads the per-User durable Files feed (
mcp_event_sources.rs:270), wakes from the existing Files signal, and uses stablename:item:cursorIDs. It intentionally returnscursor:null(mcp_events.rs:650,:696); this is not replay support. File-level write rows cannot reliably reconstruct a pastlog.createdor Task completion after content changes. Mail and deadline events also need their own durable occurrence identities. A replay cursor must track safe acknowledged/abandoned progress, not just scanned high-water. Persist an occurrence/outbox record at the existing durable writer or job commit boundary, or extend the existing feed with enough domain data. Wake signals are hints; recover from rows after a missed signal. Do not create a second content writer or Canvas mutation path (§60).Minimal payload/read pairing: CONFIRMED, with a current gap. 7a Mail payload fields are only subject and sender (
contracts/action-events.json,events.rs:55). There is no message/account ID or stable link to select the exact read tool. Add non-content identifiers while retaining the owner's subject+sender-only content rule; do not add snippets. Use the existing Mail read tools now. Curation is not required. Money amounts are already an owner decision and must not be silently deferred.Feedback loops: CONFIRMED as a design need.
Occurrencehas no actor/causation fields (calternal-plugin/src/mcp_events.rs:11). Actor identity must come from the validated mutation, not tool arguments. Internal causation and bounded automation deduplication are stronger than comparing only App Password IDs: workflows can use different credentials, and suppressing every own write can suppress an intended chain. Keep raw credential IDs private unless required.exclude_own_writesmay be a useful safe default, but choose its exact meaning and override semantics with the owner. Do not addlog.createdmerely to match the proposed example: it is not in §55's first set.Idempotent writes: CONFIRMED need; blanket key proposal — PARTLY. Existing create inputs do not offer a shared replay key. Scope keys by User/credential, action and request digest, with a retention bound and conflict rules. Store the result with the mutation outcome. One event can cause several writes, so using
eventIdalone is insufficient; use an action/step suffix. Retrying a POST after unknown transport completion must not create another Log entry, Task or transaction. This belongs with #814 and the common writer/job contracts, not just a tool hint.Subscription as authority: CONFIRMED, but 7a differs. 7a binds identity to User and App Password and rechecks switches, plugin and credential before delivery (
mcp_events.rs:245,:365,:786). Restricted Home/Plugin credentials are rejected, not filtered (:397). That is fail-closed, with a reachability gap for least-privilege clients. Grants last at most ten minutes (:44), not days; finite TTL is correct, duration is a tradeoff. The Hub stores subscriptions/queues in memory (:130), and restart drops them (docs/mcp-events.md, Decisions). Persist granted state in security state; keep signing secrets out of Home, API results and logs. This is distinct from event replay durability.Protocol discovery: CONFIRMED and newly localized. dev has no Events. 7a routes
events/*throughon_custom_request(mcp.rs:1249), but only rewritesinitialize(:1355,:1390).get_infostill declares tools only (:1240). The pinned rmcp 3.5.0 defaultServerHandler::discoverderives its result fromget_info; thereforeserver/discoverdoes not advertise Events. Test both lifecycle paths and all four supported versions. Do not equate accepting2026-07-28with implementing the Events capability.Start-small scope: PARTLY. A tested pilot is sensible, but replacing the decided first set with
log.createdand deferring Money/Share changes needs owner consent. 7a advertises twelve types;share.comment_createdhas no source and is omitted, as documented. Keep unsupported types unadvertised. Simple exact filters are good; ensure folder IDs and optional lead-time defaults work in the produced payload, not only in schema validation.Current OpenAI Events guidance requires discovery through
server/discover, retaining granted subscription state across restart, stable retry IDs, occurrence-time timestamps and bounded signed delivery. It also calls for loop and restart tests. 7a sets the payload timestamp at enqueue (mcp_events.rs:696), which is not necessarily occurrence time. Its unsubscribe DTO accepts onlydelivery.url(:73), while the guide's example also sendsdelivery.mode; closed decoding needs a compatibility test. The current draft Events sketch permits non-replayablecursor:null, but advises false truncation for that case. 7a instead sets truncation whenever a cursor is supplied. Pin the implemented draft revision and test its control envelopes, renewal and key rotation; an allowed emit-only mode does not excuse lost granted subscriptions.Additional 7a parity gap: its OpenAPI has 340 GET/HEAD/POST/PUT/PATCH/DELETE operations but the registry has 338.
mcp_event_subscriptionsandmcp_event_revokeare absent fromcontracts/actions.json. The Settings routes exist (mcp_events.rs:1088) but therefore have no generated adapter. Both are account actions under #484. The offline classifier passes because it verifies entries that exist, not that all required entries exist.Verification, files and limits
No product code, dependencies or tracked docs changed. No checkout, merge, commit, push or deploy was made. The specific read-only job overrides the shared instruction to merge before gates. No Rust/web build ran, so no build gate, screenshot, cleanup of another job's output or performance certification is claimed. Production was not contacted. Staging checks were unauthenticated and limited to the two discovery requests above.
Local untracked review artifacts:
artifacts/mcp-recritique-999/report.md,counts.py,counts.txt, start/finding comments, saved issue threads and a minimal 7a classification snapshot. They are gitignored. HEAD remainsf06679b11cde29cc0b7120fdab5f721389caf695.Static verification output, verbatim:
7a's extracted classification snapshot, verbatim:
The classifier includes OPTIONS/TRACE while the generator counts its six supported methods; these denominators are not inconsistent. These are inventory checks, not live authorization results. Known gaps: no fresh authenticated tools/list, cross-User replay, weaker-client task evaluation, native WebMCP or hosted Events lifecycle run. Historical production counts/ranking/client truncation remain historical where source cannot prove the exact response. UX gaps closed: none, because no UI changed. UX gaps left: the browser continuation, semantic Open/Today contracts, cancellation and account completion flows described above.
For the merge round, use matching rebuilt server/CLI and the required environment; do not use these static results as certification:
python3 scripts/action_registry.py --checkandpython3 scripts/parity_matrix.py --check: complete generated metadata and explicit exemptions.XUSER_CLASSIFY_ONLY=1 python3 tests/adversarial/xuser_matrix.py, thenXUSER_MATRIX_ONLY=1 tests/adversarial/run.sh: classification plus real ownership, Share and credential denials.bun apps/web/e2e/webmcp.mjs --transports-only --authorization-check --require-full-smoke: successful canonical/legacy adapter calls, continuation, account guards and matching-source parity evidence.tests/adversarial/run.sh: one time-boxed combined round, including the existing MCP/Events probes and new focused restart/discovery/revocation regressions. No external offensive probing.cargo fmt --check, per-touched-crate clippy/test, combined webbun run checkandbun run test --maxWorkers=2: implementation gates, not applicable to this review.server/discover→ event list → subscribe/challenge → delivery → refresh across restart → revoke/unsubscribe, plus duplicate/out-of-order handling. This requires #836's hosted sign-in path, not curation.flock /root/perf.lockaround the existingbench/mcp-profile.pyworkflow on the perf VM and record load. Compare each metric todocs/perf/mcp-baseline.json; measure authenticated calls, not just catalogue tokens.Decisions for the owner
These are recommendations for the design grill. They are not implemented decisions.
What does agent parity mean? Options: direct canonical tools for every authorized User action; curated defaults plus fully discoverable long tail; a curated-only surface. Recommend: preserve complete functional parity and one shared registry, with an optional curated profile after client evaluation. Every long-tail action must have a tested discovery, schema and execution path. Curated-only fails the current #484 scope.
Should generic action execution be the default? Options: canonical tools with host-side deferred loading; a single
actions_calldispatcher; both as selectable profiles. Recommend: canonical tools by default and host-side deferral where supported. A generic dispatcher has one conservative annotation set for mixed actions and can hide individual write risk from host policy. If offered, require server-side per-action confirmation/authorization and make its input an action-specific validated contract.Which categories can leave agent discovery? Options: broad category exclusions; per-action intent with equivalent capability and written exemption; no exclusions. Recommend: per-action review. Hide unavailable account/admin actions by grants; exempt hardware ceremonies and pure presentation with reasons. Keep behavioural settings, sharing, account management and transfer outcomes reachable. Approve any broader #484 change explicitly.
How can an agent complete account/credential actions? Options: ban them on both surfaces; allow account-scoped clients with fresh User authorization and protected result delivery; let data App Passwords request escalation. Recommend: the second, retaining existing denials and human completion for credential ceremonies. Never let data credentials mint account authority, and never return secrets as normal model-visible content.
What annotation and retry policy should be authoritative? Options: HTTP heuristics; reviewed action declarations; per-adapter overrides. Recommend: reviewed declarations, separate read/write, destructive, open-world, idempotence and automatic replay policy. Check declared policy against route behaviour. Additive is not the same as harmless, and If-Match is not a universal retry guarantee.
What Events durability do we promise? Options: temporary subscriptions and emit-only events; subscriptions durable for their granted TTL, with replay by event type; replay for every type immediately. Recommend: durable subscription/security state now and honest per-type replay. Reuse/extend the durable change feed and existing job writer boundaries, with an outbox when needed. No second content writer. Ten-minute grants can remain initially; choose duration using renewal cost and recovery needs rather than an arbitrary days default.
How should restricted credentials and event loops work? Options: reject restricted grants; deliver only authorized scoped events; widen grants for convenience. Recommend: scoped delivery with access checked on each attempt, introduced in a separate security-tested slice. Keep fail-closed rejection until ready. Use validated internal actor/causation and per-step idempotency; default self-trigger suppression only with a precise, documented override for intended chains.
What is the first public Events set and hosted target? Options: keep §55's decided set; replace it with the proposed five-event pilot; ship protocol-only sender first. Recommend: keep the decided set as the delivery target, ship/test self-contained types in slices and advertise only working producers. Keep Mail IDs plus subject/sender, and Money amounts as decided. Fix
server/discover, subscription restart retention and read pairing before claiming hosted interoperability. OAuth and Events can proceed in parallel; hosted acceptance depends on OAuth.Self-contained implementation issues
Reuse the named existing issues for overlapping scope. These are issue titles and proposed slices, not newly filed duplicates. Each scope has three lines, followed by dependencies and whether work can start before the grill.
A. Complete action policy declarations and grant-aware discovery (#774, #754, #833).
Dependencies: coordinate existing scopefix/notesperf/surfaces-p1 work. Can start now; permanent category removal waits for decision 3.
B. Review annotation semantics and replay policy across adapters.
Dependencies: A's declarations; #814 for replayable mutations. Can start now, with decisions 2/5 needed before generic dispatch or broad automatic retry.
C. Repair semantic contracts, names and compatibility (#817, #818, #821).
Dependencies: A's schema repair. Can start now; hiding callable aliases needs supported-client evidence.
D. Deliver structured, bounded, recoverable tool results (#836).
Dependencies: C for canonical identities; coordinate existing surfaces-p2 and scopefix work. Can start now; sensitive credential delivery follows decision 4.
E. Evaluate full, deferred and curated tool catalogues (#515).
Dependencies: A–D for comparable contracts; performance VM lock. Measurement/evaluation can start now; switching defaults or adding generic execution waits for decisions 1/2.
F. Complete hosted MCP authorization discovery (#836).
Dependencies: existing auth contract; confirm owner completion UX if needed. Can start now as existing #836 scope; it is independent of curation and local Events sender work.
G. Make #491 discovery and subscription grants survive restart.
server/discoverand initialize consistently, pin the draft and accept its valid lifecycle shapes.Dependencies: #491 implementation and migration-number coordination. Can start now; no owner reversal is needed to meet current hosted interoperability. F is required for hosted sign-in acceptance.
H. Project durable domain events and prevent repeated writes (#491, #814).
Dependencies: G, A's grant metadata and decisions 6/7/8 for replay promise, restriction support and pilot scope. Source mapping and focused tests can start now; final delivery semantics wait for those owner answers.
Response to the re-critique (from the #999 author)
Short version: the re-critique is mostly right, and it is better grounded than my original in three areas: source lines, the 7a Events branch, and owner decisions that I did not know about. I accept most corrections. I still disagree on two points, and I have one new finding that changes the verdict on finding 8. I re-checked the numbers below today against
contracts/actions.jsonondevand the live MCP server.Where I was wrong
sum(destructive)over all 333 actions, including non-MCP and admin). For the tools a data-scope App Password actually sees, it is 153 generated, plus 5 explicit legacy (167 with spec defaults), as the reply says. The argument still holds. The number was wrong.calternal_calendarhas no annotations rather than hard-coded ones. The effective result is the same, but my wording was imprecise.devonly. I did not look atjob/merge-round-7a, so several #491 notes describe gaps that 7a already handles (registry declarations viaaction-events.json,name:item:cursorIDs, App Password binding, finite grants). I also proposed changing the §55 first event set and the registry-declaration rule without knowing they were owner decisions. Withdrawn as proposals. They are at most questions for the owner.What the re-critique adds that I missed
These are the most valuable parts, and they should drive the next round:
dailyGET creates a missing Daily note, so it is labelled read-only but changes state. The profile-download GET consumes a one-use token. Method-derived hints are wrong in both directions, not only for POSTs.search,open,today,list_files, files prefs) carry no annotations, so hosts treat them as destructive.server/discoverdoes not advertise Events, because rmcp's default discover readsget_info. Subscriptions are held in memory and lost on restart. The payload timestamp is set at enqueue time. Each of these fails OpenAI's current guidance and is concrete and fixable.PropertiesPatchcollision (#833) is a real write-capability bug.Where I still disagree
1. Host-side deferral is not what happens today. The official client guidance does describe deferring definitions on the host side, and I agree that a dispatcher loses per-action annotations. But this review was run from a real MCP host (Aside), and it loaded all 290 definitions eagerly. It also truncated
mcp__Calternal__calternal_api_notifications_preview_block_reminder(66 chars;calternal_api_is 14 andmcp__Calternal__is 16, not 13 and 15) to..._preview_blo_23e9f90e. "Clients can defer" is a property of some hosts, not of the server's design. So I agree with slice E (measure full vs deferred vs curated), with one requirement: run it on the hosts calternal actually targets (ChatGPT, Claude, Aside, Claude Code, Codex), not only a deterministic reconstruction. My "20 to 30" was a starting heuristic, not a proven optimum. Agreed.2. Finding 8 is not "WRONG". It is a different bug. The
path:Notes/...form was not invented. It is what the server returns:The legacy read tools emit IDs that the legacy open tool rejects. The re-critique is right that
openparses a UUID (mcp.rs:786), but the fix is not only better help text. IDs returned by one tool must be accepted by the tool meant to open them (or the response must carry the UUID). Please fold this into slice C or D with a round-trip test: every ID-shaped field returned by a read/search tool must be accepted by the matching get/open tool.Minor: "promotional mail ranks first" was a live production response on 2026-10-03 (41 hits for
meeting, with Files and Mailscore: nullhits before the scored Log hits). It is not reproducible from source alone, as the reply says, but it is not historical either. The underlying cause the reply identifies (providers concatenated in registry order, scores not comparable) is the right one to fix.On the reply itself
The analysis is strong. Two notes so it is easier to act on:
Suggested owner answers (my view, for the grill)
server/discover, restart retention and the Mail IDs before claiming ChatGPT interoperability.Orchestrator: converged plan (pending owner answers)
Both reviews now agree on the eight decisions and slices A–H. Folding in the two additions from the author's response:
calternal_today/calternal_searchreturnpath:Notes/...andcalternal_openrejects it (-32602). Fix: acceptpath:and stable IDs everywhere a Note is opened, and return the stable calternal ID alongside. Round-trip contract test across every read→open pair.mcp__Calternal__= 16, observed truncation at 64). Deadline: the default profile is decided from E's numbers within one round after E reports, not left open.Also recorded: Events fixes on 7a that block any interoperability claim:
server/discovermust advertise Events; granted subscriptions survive restart; occurrence-time timestamps; Mail events carry message/account IDs (subject and sender stay the only content); the two missing Settings actions get registry entries.Sequencing: slices A–D and the Events fixes touch
contracts/actions.json,mcp.rsand the registry, which merge round 7b also changes heavily. Jobs start on the 7b head as soon as 7b is assembled (today), to avoid a second conflict round.