Agent Tools & MCP
An earlier version of this page listed “forty MCP tools” for sessions. That list did not exist. This page describes the tool surfaces that do exist today, and one that is built but not wired.
1. The coding-session tools (live)
core session does not use MCP. Its tools are a fixed set defined in grpc/internal/session/protocol.go, requested by the model as TOON (with a JSON fallback). There is no native function calling on this inference plane:
| Tool | Gate |
|---|---|
read_file, list_dir, write_file, git_diff | confined to the workspace; .git and symlink escapes refused |
run_shell | human y/N on every call, plus a denylist (unless a --verify tier admits the command) |
file_issue | human y/N |
browser_navigate, browser_click, browser_type, browser_read, browser_screenshot, browser_console | only with --browser; human y/N; localhost unless --browser-allow-remote |
done | ends the run |
Details: Coding Sessions.
2. The console’s Ask tools (live)
Intelligence and DataEx have a grounded question box, AskService. Its tools are read-only, in-process calls of methods the console already serves, and no Ask tool dials a tenant source. AskService.Describe lists, per scope, the tools the model may call. See Ask.
3. The MCP server library, mesh/mcp (FACE)
mesh/mcp is an in-house MCP server: JSON-RPC 2.0 over Server-Sent Events. It replaced the external mcp-go dependency, which must not be reintroduced. In the vendored copy CORE carries (grpc/vendor/github.com/org-runink/mesh/mcp), the diagnostics server registers these tools:
| Tool | Source file |
|---|---|
check_health, get_metrics_summary, system_info, actor_list, evaluate_policy, ebpf_telemetry | diagnostics_server.go |
analyze_telemetry | telemetry_tools.go |
InspectNodeState | observability_tools.go |
The mesh, MCP and object-store features are FACE-only; PULSE shares only inference and mesh/selfheal. core dev up starts the app backends with “diagnostics/MCP” enabled locally. The vendored copy may lag mesh itself, so check the mesh repo for the current list.
4. cmd/mcphost (built, not wired)
grpc/cmd/mcphost is a standalone MCP host, and infrastructure/apps/core/kustomize/operator/mcphost.yaml deploys it as core-mcphost. Its header says it exists to back the console’s tools page through MCP_RPC_URL. That wiring is gone:
- The console no longer has an
mcp.gohandler or a/mcp/rpcroute. Neither appears inregisterRoutes. MCP_RPC_URLis not projected: nothing in the console reads it.- The console’s
mcpToolstab was deleted rather than moved, so?tab=mcpToolshas no redirect (retiredTabNamesinnav.dart).
So the core-mcphost Deployment has no consumer. Whether to wire it back or remove it is pending an owner decision.
DEVGW_ROUTES. mesh/mcp mounts /mcp/rpc without a session, and its tools read platform health, metrics and policy.