You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
mcp: agent.tools.<inspector>=false still exposes the inspector's data through devframe_state_read #238
agent.tools.<inspector>: false is documented as hiding one inspector's agent tools and resources while keeping its tab. It does hide the inspector's own tools, but the generic devframe_state_read tool and the devframe://state resource still return that inspector's shared state (for example forms, router, http, http-payloads, signal-graph, ngrx-store, pipe-usage, component-tree). An agent can read the data the setting was meant to hide.
Cause
@devframes/hub and devframe mount the MCP route with a hardcoded exposeSharedState: true, and McpRouteOptions has no field to change it. The panel needs the same shared states over RPC, so they can't simply be turned off.
Once it is released and we update devframe, build a filter in packages/devtools/src/hub.ts from agent.tools that hides the shared-state keys of every inspector that is turned off. This needs a map from shared-state key to inspector, next to AGENT_INSPECTOR in packages/devtools/src/config.ts. hubMcpFor already passes an object, so the filter can be added there and merged into a caller's explicit mcp object.
Test that a turned-off inspector's keys are missing from devframe_state_read and devframe://state, and update the agent.tools docs.
Workaround
Turn the inspector off with inspectors.<name>: false, which removes its collector and state.
What happened
agent.tools.<inspector>: falseis documented as hiding one inspector's agent tools and resources while keeping its tab. It does hide the inspector's own tools, but the genericdevframe_state_readtool and thedevframe://stateresource still return that inspector's shared state (for exampleforms,router,http,http-payloads,signal-graph,ngrx-store,pipe-usage,component-tree). An agent can read the data the setting was meant to hide.Cause
@devframes/hubanddevframemount the MCP route with a hardcodedexposeSharedState: true, andMcpRouteOptionshas no field to change it. The panel needs the same shared states over RPC, so they can't simply be turned off.Fix
exposeSharedState?: boolean | ((key: string) => boolean)toMcpRouteOptions, withtrueas the default. It is open and waiting on a maintainer review.packages/devtools/src/hub.tsfromagent.toolsthat hides the shared-state keys of every inspector that is turned off. This needs a map from shared-state key to inspector, next toAGENT_INSPECTORinpackages/devtools/src/config.ts.hubMcpForalready passes an object, so the filter can be added there and merged into a caller's explicitmcpobject.devframe_state_readanddevframe://state, and update theagent.toolsdocs.Workaround
Turn the inspector off with
inspectors.<name>: false, which removes its collector and state.Blocked on devframes/devframe#444.