feat: add MCP server URL validation to hermes-config-template contract #114

Merged
mumuni-bot merged 4 commits from fm/hermes-config-mcp-url-validation into master 2026-09-17 13:22:32 +00:00
Showing only changes of commit 077972fa2b - Show all commits
+8
View File
@@ -150,6 +150,8 @@ mcp_servers:
url: https://litellm.sysloggh.net/mcp
headers:
x-litellm-api-key: "Bearer <AGENT_KEY>" # Rule 15: must be a REAL key (sk-...), not an env-var name
# Note: MCP endpoint requires Accept: application/json, text/event-stream header
# This is handled by the MCP client library; don't add to config
# ─── Compression ───
compression:
@@ -237,6 +239,12 @@ MCP server entries in `mcp_servers:` must follow the format shown in the Templat
- For template-based config generation: substitute the agent's key from the agent_keys table
- For manual config updates: retrieve the key from the vault and insert the literal value
**Verification (2026-08-07):**
- Tested MCP initialize handshake against litellm.sysloggh.net/mcp with real key
- Confirmed: 200 response with `serverInfo.name: "litellm-mcp-server"`
- Confirmed: virtual keys have MCP access (tools/list returns 200, not 403)
- Key requirement: must be a valid LiteLLM virtual key (HTTP 200 on /v1/models)
## Violation Classification
When reporting findings, separate POLICY observations from FAULT findings: