Skip to content

Name this eip-mcp everywhere, including the deploy templates - #10

Merged
exploitintel merged 1 commit into
mainfrom
docs/name-eip-mcp-consistently
Sep 11, 2026
Merged

exploitintel merged 1 commit into
mainfrom
docs/name-eip-mcp-consistently

Conversation

@exploitintel

Copy link
Copy Markdown
Owner

The repository, PyPI distribution and canonical executable have been eip-mcp since 3.0.0. AGENTS.md:3-4 says so, three lines under a title that still read # eip-mcp-v3.

The part that reaches users

deploy/systemd/ shipped eip-mcp-v3.service and eip-mcp-v3.env.example, installing to /opt/eip/eip-mcp-v3 and executing the legacy alias console script. docs/self-hosting.md walked a public reader through that entire procedure.

Production has run eip-mcp at /opt/eip/eip-mcp since 2026-08-17, so anyone following the published self-hosting guide built something that did not match the project or its own documentation.

I checked the renamed unit against what ovh2 actually runs rather than assuming:

WorkingDirectory=/opt/eip/eip-mcp
EnvironmentFile=/etc/eip-v3/eip-mcp.env
ExecStartPre=/usr/bin/test -x /opt/eip/eip-mcp/.venv/bin/eip-mcp
ExecStart=/opt/eip/eip-mcp/.venv/bin/eip-mcp --transport streamable-http --host 127.0.0.1 --port 13003 --path /mcp

Identical. The eip-mcp-v3 console script stays as the legacy alias, which is deliberate and documented.

Three more wrong claims

Claim Reality
AGENTS.md:77 SDK mcp>=2.0.0,<3 pyproject.toml:25 pins <2.1, since 2.1.0 stopped propagating messages raised during argument validation
declared_arguments.py is "the ledger tying every declared parameter to an observable effect" it is the gate refusing undeclared arguments; its own docstring says there is deliberately no second list. The ledger is in tests/, as AGENTS.md:128-129 already says
pagination unreachable "on all three paginated tools" ten tools declare a cursor. Count dropped so it cannot rot again

Verification

1970 passed, 232 skipped, ruff clean. tests/test_host_allowlist_matching.py:31 referenced the old template filename and failed on the rename, which is the test doing its job; it now matches.

The auditor separately confirmed the 19-tool list, that all 19 carry the read-only annotation, and every documented bound and env default.

The repository, PyPI distribution and canonical executable have been eip-mcp
since 3.0.0, and AGENTS.md says so three lines under a title that still read
eip-mcp-v3. The deploy templates never followed: deploy/systemd shipped
eip-mcp-v3.service and eip-mcp-v3.env.example installing to
/opt/eip/eip-mcp-v3 and executing the legacy alias, and docs/self-hosting.md
walked a public reader through that whole procedure. Production has run
eip-mcp at /opt/eip/eip-mcp since 2026-08-17, so anyone following the
self-hosting guide built something that did not match the project.

The renamed unit is now byte-for-byte the shape of the unit ovh2 actually runs,
which I checked against the host rather than assuming.

Three more claims were wrong. AGENTS.md gave the SDK range as mcp>=2.0.0,<3;
pyproject pins <2.1 since 2.1.0 stopped propagating messages raised during
argument validation. It described declared_arguments.py as the ledger tying
parameters to effects, when that module is the gate refusing undeclared
arguments and its own docstring says there is deliberately no second list; the
ledger is in tests, as AGENTS.md correctly says elsewhere. And it said
pagination was unreachable on "all three paginated tools" when ten declare a
cursor, so the count is dropped rather than left to rot again.

tests/test_host_allowlist_matching.py referenced the old template filename and
now matches; that it failed on the rename is the test doing its job.
@claude

claude Bot commented Sep 11, 2026

Copy link
Copy Markdown

Reviewed against the checklist for this repo (corpus-text escaping, derived judgments, stored-analysis fail-open, PoC token leakage, unbounded output, fabricated values, host-validation/transport-security weakening, scope creep). None of that surface is touched here — this is a pure naming/doc consistency fix (eip-mcp-v3 → eip-mcp in AGENTS.md, the systemd unit/env template, docs/self-hosting.md, and the one test path that pins against them).

Spot-checked the two corrected factual claims directly against source rather than taking the PR description at face value:

  • pyproject.toml:25 does pin mcp>=2.0.0,<2.1 — the AGENTS.md SDK constraint text now matches.
  • declared_arguments.py's docstring does describe itself as the gate reading accepted names back out of published schemas ("no second list to drift"), not a ledger — the AGENTS.md description now matches the code's own self-description.

Also confirmed no stale eip-mcp-v3 path references remain anywhere (opt/eip/eip-mcp-v3, etc/eip-v3/eip-mcp-v3.env), and that the deliberately-kept legacy alias (eip-mcp-v3 console script entry point, referenced in pyproject.toml, the CI quality/release workflows) was correctly left alone rather than swept up by the rename.

No functional or security-relevant behavior changes. No inline comments.

@exploitintel
exploitintel merged commit bbff6bc into main Sep 11, 2026
4 checks passed
@exploitintel
exploitintel deleted the docs/name-eip-mcp-consistently branch September 11, 2026 07:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant