feat(mcp): curated exclude list for cloudflare + glob tool filters + default_excluded manifests

The cloudflare entry's 3,320-endpoint surface is ~43% product families a
personal/dev account never touches (Zero Trust org-fleet suite, Magic
Transit/WAN, Cloudforce One, Radar analytics, API Shield, legacy
migration surfaces). Ship a 34-pattern curated exclude list in the
manifest: 3,320 -> 1,905 tools kept, and everything Cloudflare adds
later stays enabled by default.

Mechanism, two small extensions:
- tools/mcp_tool.py: tools.include/exclude entries containing glob
  metacharacters now match via fnmatch (plain names stay exact-match),
  so a product family is one pattern instead of hundreds of stale
  literals.
- hermes_cli/mcp_catalog.py: manifests may declare
  tools.default_excluded (mutually exclusive with default_enabled);
  install writes it to tools.exclude and skips the probe/checklist —
  a 3,320-row curses checklist is not a UX. Prior user include
  selections still win on reinstall.

Verified by replaying the real filter functions over the live-probed
3,320-tool list: 1,415 excluded, zero overmatch against a per-product
target audit; DNS/Workers/R2/D1/tunnels/Access/AI kept.
This commit is contained in:
Teknium 2026-07-20 08:51:47 -07:00
parent ce0defe4d8
commit 58c97b9ddd
No known key found for this signature in database
6 changed files with 295 additions and 14 deletions

View file

@ -3832,6 +3832,59 @@ class TestMCPSelectiveToolLoading:
"mcp__ink_exclude__list_services",
]
def test_exclude_filter_supports_glob_patterns(self):
"""Glob entries in tools.exclude match families of tool names."""
config = {
"url": "https://mcp.example.com",
"tools": {"exclude": ["*_radar_*", "docs"]},
}
registered, _ = self._run_discover(
"ink_glob",
[
"get_radar_http_summary",
"post_radar_scans",
"docs",
"get_zones_dns_records",
],
config,
session=SimpleNamespace(),
)
assert registered == ["mcp__ink_glob__get_zones_dns_records"]
def test_include_filter_supports_glob_patterns(self):
"""Glob entries in tools.include whitelist families of tool names."""
config = {
"url": "https://mcp.example.com",
"tools": {"include": ["*_dns_*"]},
}
registered, _ = self._run_discover(
"ink_glob_inc",
["get_zones_dns_records", "post_zones_dns_records", "docs"],
config,
session=SimpleNamespace(),
)
assert registered == [
"mcp__ink_glob_inc__get_zones_dns_records",
"mcp__ink_glob_inc__post_zones_dns_records",
]
def test_plain_exclude_names_do_not_glob_match(self):
"""Entries without metacharacters stay exact-match (no surprise hits)."""
config = {
"url": "https://mcp.example.com",
"tools": {"exclude": ["docs"]},
}
registered, _ = self._run_discover(
"ink_exact",
["docs", "docs_search", "get_docs"],
config,
session=SimpleNamespace(),
)
assert registered == [
"mcp__ink_exact__docs_search",
"mcp__ink_exact__get_docs",
]
def test_include_filter_skips_utility_tools_without_capabilities(self):
config = {
"url": "https://mcp.example.com",