How MCP Tools Behave
How tools from connected MCP servers are named, capped, confirmed and kept alive.
Tool naming
MCP-exposed tools are auto-registered with the format:
mcp__<server_name>__<tool_name>
Example: mcp__github__create_issue, mcp__sqlite-notes__read_query.
Result size cap
Each MCP tool result is capped at 1 MiB. When exceeded, the result is truncated with the marker:
[mcp output truncated: <total> bytes total, <kept> kept]
This avoids OpenAI Responses API's 10 MB single-tool-output limit triggering a same-signature retry storm. SQLite SELECT * on a large table will hit this — add LIMIT / WHERE.
Confirm behavior
MCP tools route through the most conservative defaults:
- Every MCP tool call goes through the same confirm gate as a built-in tool, under whatever permission mode the request carries
- No per-server
read_onlytoggle — Agenvoy does not extend trust to third-party servers because their behavior is unverifiable (a Slack MCP could silently send messages, a Filesystem MCP could silently write files)
Trust is granted per tool, not per server: /mcp → server → tools (or POST /v1/allowlist with a tool block) replaces the auto-approve entries for one prefix, leaving unrelated rules alone. Every entry must start with that prefix, and prefix* collapses the rest into a whole-server grant. The list lives in ~/.config/agenvoy/allow_tool.
Lifecycle
- Startup:
app.NewMCPcallsmcp.New(ctx, sid), thenRegisterAll(ctx), then startsWatch(ctx), before the agent registry is built; clients close on shutdown - Live tool refresh: clients subscribe to the server's
notifications/tools/list_changedand re-register that server's tools when its catalog changes — no restart needed for a server that adds or drops tools - Server instructions: whatever a server declares as its instructions is surfaced into the agent system prompt, so per-server usage rules reach the model
- Per-server failures: a start or tool-list failure logs a warning and skips that server; core functionality never blocks
- Manual recovery:
POST /v1/mcp/reconnectreconnects every client and re-registers tools;/mcp→ server → reconnect in the TUI does the same for one server