From 7400dfd833f86d775d69381b926f17a4b58a69aa Mon Sep 17 00:00:00 2001 From: abiba-bot Date: Thu, 17 Sep 2026 12:33:52 +0000 Subject: [PATCH] fix: add MCP server checks to audit-hermes-config.py Implement Rule 15 automated enforcement for MCP servers: - Validate MCP server URLs against known endpoints (ra-h-os, litellm) - Check for authentication headers on MCP server configs - Warn if header values look like env-vars instead of literal keys - Warn if no auth header is present This ensures the MCP URL/header invariants from the prose contract are enforced at the earliest shared boundary (before config application). --- audit-hermes-config.py | 35 +++++++++++++++++++++++++++++++++++ 1 file changed, 35 insertions(+) diff --git a/audit-hermes-config.py b/audit-hermes-config.py index 2c3d109..f2e6d8c 100644 --- a/audit-hermes-config.py +++ b/audit-hermes-config.py @@ -262,6 +262,41 @@ def audit(path): f"{field_path} = {value!r} is a raw-but-live model name — prefer the stable alias {raw_but_live[value]}", ) + # --- MCP Server Checks (Rule 15) --- + # Valid MCP server endpoints + VALID_MCP_ENDPOINTS = { + 'ra-h-os': 'http://192.168.68.65:3100/mcp', + 'litellm': 'https://litellm.sysloggh.net/mcp', + } + + # Check MCP servers if they exist + mcp_servers = cfg.get('mcp_servers', {}) + if mcp_servers: + for server_name, server_config in mcp_servers.items(): + url = server_config.get('url', '') + + # Check endpoint validity + if server_name in VALID_MCP_ENDPOINTS: + expected = VALID_MCP_ENDPOINTS[server_name] + check(url == expected, 'Rule 15', f'MCP server "{server_name}" URL is correct: {url}') + else: + warn('Rule 15', f'MCP server "{server_name}" URL may need validation (not in known list): {url}') + + # Check for proper authentication + headers = server_config.get('headers', {}) + has_auth = False + for key, value in headers.items(): + if 'key' in key.lower() or 'auth' in key.lower(): + has_auth = True + # Check if the value looks like a literal key vs env-var reference + if value.startswith('Bearer ') and value[7:].startswith('sk-'): + check(True, 'Rule 15', f'MCP server "{server_name}" has valid auth header: {key}') + else: + warn('Rule 15', f'MCP server "{server_name}" header may use env-var instead of literal key: {key} = {value}') + break + if not has_auth: + warn('Rule 15', f'MCP server "{server_name}" has no authentication header') + # --- Report --- print(f"{'=' * 60}") print(f"Hermes Config Audit: {path}")