Custom MCP configuration and secret patches use ordinary JavaScript records keyed by server/header/env names. The special key proto is accepted by the configuration path but is treated as a prototype setter or omitted when those records are assembled/persisted, so the configured entry/value disappears after reload or never reaches the adapter. Reject this key consistently at validation or use a safe key-preserving representation throughout the config and secret paths.
Custom MCP configuration and secret patches use ordinary JavaScript records keyed by server/header/env names. The special key proto is accepted by the configuration path but is treated as a prototype setter or omitted when those records are assembled/persisted, so the configured entry/value disappears after reload or never reaches the adapter. Reject this key consistently at validation or use a safe key-preserving representation throughout the config and secret paths.