diff --git a/audit-hermes-config.py b/audit-hermes-config.py index 2c3d109..f2e6d8c 100644 --- a/audit-hermes-config.py +++ b/audit-hermes-config.py @@ -262,6 +262,41 @@ def audit(path): f"{field_path} = {value!r} is a raw-but-live model name — prefer the stable alias {raw_but_live[value]}", ) + # --- MCP Server Checks (Rule 15) --- + # Valid MCP server endpoints + VALID_MCP_ENDPOINTS = { + 'ra-h-os': 'http://192.168.68.65:3100/mcp', + 'litellm': 'https://litellm.sysloggh.net/mcp', + } + + # Check MCP servers if they exist + mcp_servers = cfg.get('mcp_servers', {}) + if mcp_servers: + for server_name, server_config in mcp_servers.items(): + url = server_config.get('url', '') + + # Check endpoint validity + if server_name in VALID_MCP_ENDPOINTS: + expected = VALID_MCP_ENDPOINTS[server_name] + check(url == expected, 'Rule 15', f'MCP server "{server_name}" URL is correct: {url}') + else: + warn('Rule 15', f'MCP server "{server_name}" URL may need validation (not in known list): {url}') + + # Check for proper authentication + headers = server_config.get('headers', {}) + has_auth = False + for key, value in headers.items(): + if 'key' in key.lower() or 'auth' in key.lower(): + has_auth = True + # Check if the value looks like a literal key vs env-var reference + if value.startswith('Bearer ') and value[7:].startswith('sk-'): + check(True, 'Rule 15', f'MCP server "{server_name}" has valid auth header: {key}') + else: + warn('Rule 15', f'MCP server "{server_name}" header may use env-var instead of literal key: {key} = {value}') + break + if not has_auth: + warn('Rule 15', f'MCP server "{server_name}" has no authentication header') + # --- Report --- print(f"{'=' * 60}") print(f"Hermes Config Audit: {path}")