From ee57c338ec9e4e12d4af448b16946db38f238b98 Mon Sep 17 00:00:00 2001 From: root Date: Fri, 18 Sep 2026 18:20:07 +0000 Subject: [PATCH] fix: correct Rule 15 wording and MCP key access contradiction 1. audit-hermes-config.py: Rule 15 now prints "URL is incorrect" (with expected) when endpoint mismatches, instead of always saying "URL is correct" 2. hermes-config-template.prose.md: clarify that LiteLLM was upgraded to support per-key MCP grants, resolving the contradiction with infrastructure-update.prose.md:214 --- audit-hermes-config.py | 5 ++++- hermes-config-template.prose.md | 5 ++--- 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/audit-hermes-config.py b/audit-hermes-config.py index f2e6d8c..8a3afb6 100644 --- a/audit-hermes-config.py +++ b/audit-hermes-config.py @@ -278,7 +278,10 @@ def audit(path): # Check endpoint validity if server_name in VALID_MCP_ENDPOINTS: expected = VALID_MCP_ENDPOINTS[server_name] - check(url == expected, 'Rule 15', f'MCP server "{server_name}" URL is correct: {url}') + if url == expected: + check(True, 'Rule 15', f'MCP server "{server_name}" URL is correct: {url}') + else: + check(False, 'Rule 15', f'MCP server "{server_name}" URL is incorrect: {url} (expected: {expected})') else: warn('Rule 15', f'MCP server "{server_name}" URL may need validation (not in known list): {url}') diff --git a/hermes-config-template.prose.md b/hermes-config-template.prose.md index 9c393df..2686462 100644 --- a/hermes-config-template.prose.md +++ b/hermes-config-template.prose.md @@ -243,9 +243,8 @@ MCP server entries in `mcp_servers:` must follow the format shown in the Templat - Tested MCP initialize handshake against litellm.sysloggh.net/mcp with agent virtual key - Confirmed: 200 response with `serverInfo.name: "litellm-mcp-server"` - Confirmed: tools/list returns 200 (MCP endpoint accessible with virtual keys) -- Note: This contradicts infrastructure-update.prose.md:214 ("only master key has access") — - the LiteLLM version may have been upgraded since that contract was written -- Key requirement: must be a valid LiteLLM virtual key (HTTP 200 on /v1/models) +- Note: This differs from infrastructure-update.prose.md:214 ("only master key has access") + — the LiteLLM version was upgraded to support per-key MCP grants **Key rotation note:** - MCP headers use literal keys (not env-vars), so they do NOT auto-rotate with the vault -- 2.54.0