Repository navigation
[tpp][codex] pass multi-agent metadata to MCP tools call - #27495
miaolin-oai wants to merge 1 commit into
Conversation
03ec350 to
e55626e
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e55626ed32
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
e55626e to
0738d61
Compare
1a43ba3 to
fa42133
Compare
fa42133 to
12e1ab8
Compare
12e1ab8 to
4626154
Compare
|
Convert to draft as we're revisiting security requirement |
|
For the security review, I would treat The fields that seem useful without leaking transcript context are:
I would also add a negative test that an MCP server does not receive prompt text, tool arguments, environment, cwd, or other client/session fields unless they are explicitly added to the allowlist. That makes future provenance fields easier to add without reopening the same security question. Generated with ax. |
|
Closing this pull request because it has had no updates for more than 14 days. If you plan to continue working on it, feel free to reopen or open a new PR. |
Summary
agent_pathto Codex MCP request turn metadatahas_spawned_subagentmetadata, computed from persisted thread-spawn edges/rootfor root sessions and preserve thread-spawn subagent paths such as/root/workeragent_pathandhas_spawned_subagentout of the normal turn metadata header; they are only emitted in MCP request_metaNotes
Search Service MCP receives Codex turn metadata through MCP request
_meta["x-codex-turn-metadata"]. This change makes the current agent path visible there, so Search Service MCP can infer direct subagent usage withagent_path != "/root".It also adds
has_spawned_subagent, which is computed at MCP call time by checking the current thread ID against the persistedthread_spawn_edgesstate usinglist_thread_spawn_children. This counts both open and closed spawned subagents and avoids scanning conversation history.Example metadata:
{ "x-codex-turn-metadata": { "agent_path": "/root", "has_spawned_subagent": true } }Slack context: https://openai-corpws.slack.com/archives/C0AP7B5JY0K/p1781124325871739?thread_ts=1781123263.746089&cid=C0AP7B5JY0K
This does not change the standalone
v1/alpha/searchrequest body directly.Testing
cargo fmt --allfromcodex-rscargo check -p codex-corecargo test -p codex-core mcp_tool_call_request_meta_includes_has_spawned_subagentcargo test -p codex-core turn_metadata_state_includes_agent_path_only_in_request_metacargo test -p codex-core turn_metadata_state_ignores_client_reserved_metadata_before_startjustwas not installed in this environment, so I used the underlying Rust toolchain directly.