Skip to content

feat(control-plane): getGithubApp MCP tool hands the agent the App install link - #2015

Closed
spacedragon wants to merge 1 commit into
mainfrom
dev/yulong/mcp-get-github-app
Closed

spacedragon wants to merge 1 commit into
mainfrom
dev/yulong/mcp-get-github-app

Conversation

@spacedragon

Copy link
Copy Markdown
Contributor

What

Adds one read tool to the admin MCP catalog: getGithubApp → GET /github/app. It returns whether the deployment has a GitHub App, its slug, and a fresh installUrl — the signed, one-shot, org-bound link to install the App on GitHub for the caller's organization.

  • http/mcp/tools.ts: the tool, placed before listGithubInstallations, with a description that tells the model when to call it (installations empty, or none covering the repository's owner) and to hand the link to the user verbatim.
  • test/integration/mcp.route.test.ts: added to the GitHub-gated set so the route-reach guard probes it against the GitHub-configured app.
  • docs/designs/agent-assistant.md §6.2: catalog row.

Why

Seen in a webchat session with the built-in agent: when the GitHub App was not installed, the create-agent flow could only point at a console tab. No tool returned the install link, and the skill cannot construct it, because the route mints a signed state per call that the setup callback needs to bind the installation to the org.

Reviewer notes

  • Read tool, GET only. The route keeps its own denyViewerWrite gate (minting the link starts a connection change); a viewer's 403 is relayed as-is and the tool description says an editor/owner has to open the link.
  • Each call mints a new state row (15-minute TTL, consumed once). The paired skill change tells the agent to call it only when an installation is actually missing and to fetch a fresh one rather than reuse an old link.
  • Pairs with feat: a missing GitHub App installation gets the install link, not a console page agentconnect-skill#5, which makes the code-reviewer template use it.

Verification

  • vitest run src/http/mcp/tools.test.ts — 37 passed.
  • vitest run --project integration test/integration/mcp.route.test.ts — 34 passed (includes "every registered tool reaches a real route").
  • Prettier clean on the three files.

🤖 Generated with Claude Code

…stall link

When the built-in agent finds no GitHub App installation covering a
repository's owner, all it could do was point at a console tab: nothing in
the admin catalog returned the install link, and the link cannot be hand-
built — GET /github/app mints a signed, one-shot, org-bound state per call.

Expose that route as the getGithubApp read tool. It relays the route's own
viewer gate (403: may view, not connect) and 404 (no App on this
deployment) unchanged. The integration route-reach guard probes it against
the GitHub-configured app like the other GitHub reads.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

@agentconnect-md-test agentconnect-md-test Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed revision b564f074a790f51f68757a67bee7c22477228c88. No blocking regressions found. The new tool reuses the caller-scoped GitHub App route, preserves its viewer restriction, and returns the existing signed, one-shot install link unchanged.

git diff --check passed. The focused MCP unit tests could not run: dependencies are absent, and pnpm’s automatic install failed on a restricted filesystem path. The integration suite was not run.

sent by review-bot (Codex · gpt-6-astra) · open in session

@zfy0701
zfy0701 deleted the dev/yulong/mcp-get-github-app branch September 28, 2026 02:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant