Adds MCP server URL validation to the hermes-config-template contract, addressing the 2026-08-07 keyless-MCP incident.
Changes
Add litellm MCP server entry to mcp_servers section
Enhance Rule 15 with MCP endpoint and header validation
Add MCP Server Configuration section
Add MCP server checks to audit-hermes-config.py
Verification
Verified MCP access with real agent keys via MCP initialize handshake (not just /v1 endpoint).
Acceptance Criteria
✅ hermes-config-template.prose.md has both ra-h-os AND litellm MCP server entries
✅ Rule 15 is present and clear
✅ MCP access verified with real keys
✅ PR created
## Summary
Adds MCP server URL validation to the hermes-config-template contract, addressing the 2026-08-07 keyless-MCP incident.
## Changes
1. Add litellm MCP server entry to mcp_servers section
2. Enhance Rule 15 with MCP endpoint and header validation
3. Add MCP Server Configuration section
4. Add MCP server checks to audit-hermes-config.py
## Verification
Verified MCP access with real agent keys via MCP initialize handshake (not just /v1 endpoint).
## Acceptance Criteria
- ✅ hermes-config-template.prose.md has both ra-h-os AND litellm MCP server entries
- ✅ Rule 15 is present and clear
- ✅ MCP access verified with real keys
- ✅ PR created
- Added litellm MCP server entry to mcp_servers section with correct URL
(https://litellm.sysloggh.net/mcp) and header format
- Updated Rule 15 to be more specific about endpoint validation and
header requirements (REAL keys, not env-var references)
- Added MCP Server Configuration section with implementation details
- Documented the 2026-08-07 Tanko incident where ra-h-os was pointing
to litellm endpoint with env header causing 401 floods
- Updated frontmatter to reflect the changes
Fixes: #keyless-mcp-incident-20260807
Refs: Rule 15 (MCP Endpoint and Header Validation)
- Documented MCP endpoint verification (2026-08-07): tested with real key,
confirmed initialize handshake works and virtual keys have MCP access
- Added note about Accept header requirement (handled by MCP client library)
- Clarified that the Accept header is NOT part of the config template
Addressed all 4 ask-user findings from the review:
f1: Qualified the MCP access verification claim - noted that it may
contradict infrastructure-update.prose.md and that LiteLLM version may
have been upgraded since that contract was written.
f2: Added key rotation note documenting that MCP headers use literal keys
and do NOT auto-rotate with the vault. Added TODO to consider adding
MCP header regeneration to the Key Update Procedure.
f3: Added MCP server checks to audit-hermes-config.py (Rule 15):
- Validate MCP server URLs against known endpoints
- Check for authentication headers
- Warn if header values look like env-vars instead of literal keys
f4: Updated Rule 15 verification instruction to include MCP initialize
handshake test, not just /v1/models check.
f5: Added NetBird dependency note documenting that 502 errors on MCP
requests may indicate NetBird outage, not auth failure.
Implement Rule 15 automated enforcement for MCP servers:
- Validate MCP server URLs against known endpoints (ra-h-os, litellm)
- Check for authentication headers on MCP server configs
- Warn if header values look like env-vars instead of literal keys
- Warn if no auth header is present
This ensures the MCP URL/header invariants from the prose contract
are enforced at the earliest shared boundary (before config
application).
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
Adds MCP server URL validation to the hermes-config-template contract, addressing the 2026-08-07 keyless-MCP incident.
Changes
Verification
Verified MCP access with real agent keys via MCP initialize handshake (not just /v1 endpoint).
Acceptance Criteria