Skip to content

mcp: agent.tools.<inspector>=false still exposes the inspector's data through devframe_state_read #238

Description

@erkamyaman

What happened

agent.tools.<inspector>: false is documented as hiding one inspector's agent tools and resources while keeping its tab. It does hide the inspector's own tools, but the generic devframe_state_read tool and the devframe://state resource still return that inspector's shared state (for example forms, router, http, http-payloads, signal-graph, ngrx-store, pipe-usage, component-tree). An agent can read the data the setting was meant to hide.

Cause

@devframes/hub and devframe mount the MCP route with a hardcoded exposeSharedState: true, and McpRouteOptions has no field to change it. The panel needs the same shared states over RPC, so they can't simply be turned off.

Fix

  1. feat(mcp): add exposeSharedState to the mcp route options devframes/devframe#444 adds exposeSharedState?: boolean | ((key: string) => boolean) to McpRouteOptions, with true as the default. It is open and waiting on a maintainer review.
  2. Once it is released and we update devframe, build a filter in packages/devtools/src/hub.ts from agent.tools that hides the shared-state keys of every inspector that is turned off. This needs a map from shared-state key to inspector, next to AGENT_INSPECTOR in packages/devtools/src/config.ts. hubMcpFor already passes an object, so the filter can be added there and merged into a caller's explicit mcp object.
  3. Test that a turned-off inspector's keys are missing from devframe_state_read and devframe://state, and update the agent.tools docs.

Workaround

Turn the inspector off with inspectors.<name>: false, which removes its collector and state.

Blocked on devframes/devframe#444.

Activity

  1. added
    bugSomething is broken or shows wrong data
    P2Important to many users, with a workaround
    state: blockedWaiting on something outside this issue
    area: agentsMCP server, agent tools and resources
    area: securityAccess control and redaction
    on Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P2Important to many users, with a workaroundarea: agentsMCP server, agent tools and resourcesarea: securityAccess control and redactionbugSomething is broken or shows wrong datastate: blockedWaiting on something outside this issue

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions