What happened?
tools.eager accepts dynamic tool names such as mcp__* and computer_use__*, but a typo in one of those names is accepted silently.
For example, configuring:
{
"tools": {
"eager": ["mcp__githb__create_issue"]
}
}
activates the allowlist without matching a discovered tool. As a result, every non-exempt tool is deferred to tool_search, with no startup diagnostic explaining the unexpected tool surface.
This is the remaining diagnostic gap from #10400. Its other items are covered by #10479.
What did you expect to happen?
After the relevant dynamic tool-discovery cycle completes, Qwen Code should warn when a configured mcp__* or computer_use__* eager entry matches no registered tool. Valid entries must remain silent.
Client information
Observed against current main during repository maintenance. The behavior is configuration-driven and does not depend on a particular provider or operating system.
Anything else we need to know?
Do not validate these names during PermissionManager.initialize(): MCP tools can be registered after initialization, so that would produce false warnings. The validation needs a registry-aware completion boundary that handles incremental MCP discovery and canonical tool names.
Suggested coverage:
- typoed MCP and Computer Use entries warn;
- valid dynamic entries do not warn;
- late registration does not produce a premature warning;
- warnings are emitted once per unmatched entry.
What happened?
tools.eageraccepts dynamic tool names such asmcp__*andcomputer_use__*, but a typo in one of those names is accepted silently.For example, configuring:
{ "tools": { "eager": ["mcp__githb__create_issue"] } }activates the allowlist without matching a discovered tool. As a result, every non-exempt tool is deferred to
tool_search, with no startup diagnostic explaining the unexpected tool surface.This is the remaining diagnostic gap from #10400. Its other items are covered by #10479.
What did you expect to happen?
After the relevant dynamic tool-discovery cycle completes, Qwen Code should warn when a configured
mcp__*orcomputer_use__*eager entry matches no registered tool. Valid entries must remain silent.Client information
Observed against current
mainduring repository maintenance. The behavior is configuration-driven and does not depend on a particular provider or operating system.Anything else we need to know?
Do not validate these names during
PermissionManager.initialize(): MCP tools can be registered after initialization, so that would produce false warnings. The validation needs a registry-aware completion boundary that handles incremental MCP discovery and canonical tool names.Suggested coverage: