From 93fb0d8e1e9317b2c7287902d55fc6fa5ef5404d Mon Sep 17 00:00:00 2001 From: root Date: Fri, 7 Aug 2026 21:33:59 +0000 Subject: [PATCH] feat(contracts): add MCP URL validation and verify virtual keys on LiteLLM --- hermes-config-template.prose.md | 12 ++++++++++-- hermes-key-enforcement.prose.md | 6 +++--- 2 files changed, 13 insertions(+), 5 deletions(-) diff --git a/hermes-config-template.prose.md b/hermes-config-template.prose.md index 80e6dc2..028bcad 100644 --- a/hermes-config-template.prose.md +++ b/hermes-config-template.prose.md @@ -5,8 +5,7 @@ description: > Standard Hermes configuration template for Syslog Solution LLC agents. Enforces shared infrastructure setup (Firecrawl, SearXNG, local models, RA-H OS MCP) while keeping agent-specific API keys and model choices. - UPDATED 2026-07-16: Compression model is the stable alias `strix-moe` (NOT `ornith-1.0-35b`, - which LiteLLM does not serve). All 3 GPUs verified at 128K (reduced from 256K 2026-07-17 for stability). + UPDATED 2026-08-07: Added Rule 15 (MCP Validation) from the 2026-08-07 keyless-MCP incident. Added Rule 12 (Context-Issue Diagnostic) + Rule 13 (.env fallback enforcement) from the 2026-07-16 Mumuni root-cause investigation (WAL #1300). UPDATED 2026-07-12: GPU workload redistributed. Compression → Strix Halo. RTX 3090 context verified at 128K. Infisical .env fallback required (Rule 3/13). @@ -396,6 +395,15 @@ curl -s -o /dev/null -w '%{http_code}' -H "Authorization: Bearer $K" http://192. - **Audit script**: Run `python3 /root/prose-contracts/audit-hermes-config.py ` before and after any config change to catch this and all other rule violations. +### Rule 15: MCP Endpoint and Header Validation (ADDED 2026-08-07) +- Every MCP server entry must point at the correct endpoint: + - ra-h-os = http://192.168.68.65:3100/mcp + - litellm = https://litellm.sysloggh.net/mcp +- MCP entries must carry a REAL key value in the header. + - Avoid using env-var names like LITELLM_API_KEY in the header; they do not resolve for MCP + endpoints and result in "Malformed API Key" floods. + - Ensure the header value is the actual key (e.g., `sk-...`). + ## Execution 1. **Check current config** — Read the target agent's config.yaml diff --git a/hermes-key-enforcement.prose.md b/hermes-key-enforcement.prose.md index 7f2bfaf..544b2e7 100644 --- a/hermes-key-enforcement.prose.md +++ b/hermes-key-enforcement.prose.md @@ -190,10 +190,10 @@ litellm_settings: |-------|-----|-----|---------------|------------|--------|-----------------|---------------| | Tanko | 112 | .122 | `tanko` | Infisical vault | ✅ Fixed | `infisical run` | 20:17 UTC Jul 5 | | Mumuni | 100 (abiba) | .24 | `mumuni` | Infisical vault | ✅ Fixed | Pi Hermes gateway | 2026-07-27 | -| Koby | 111 | ? | `koby` | Infisical vault | ✅ Fixed | `infisical run` | 23:30 UTC Jul 5 | -| Koonimo | 113 | ? | `koonimo` | Infisical vault | ✅ Fixed | `infisical run` (migrated 2026-07-11) | 2026-07-11 | +| Koby | 111 | .129 | `koby` | Infisical vault | ✅ Fixed | `infisical run` | 23:30 UTC Jul 5 | +| Koonimo | 113 | .113 | `koonimo` | Infisical vault | ✅ Fixed | `infisical run` (migrated 2026-07-11) | 2026-07-11 | | Abiba | 100 | .65 | `abiba-pi` | Infisical vault | ✅ N/A (pi native) | — | 19:44 UTC Jul 5 | -| Kagenz0 | 105 | ? | — | — | ❌ DOWN | — | 19:14 EDT Jul 4 | +| Kagenz0 | 105 | .14 | — | — | ❌ DOWN | — | 19:14 EDT Jul 4 | > **Note**: CT hostnames (tdunna, baggy) differ from agent identities (koby, koonimo). > LiteLLM key aliases use agent identity, not CT hostname.