Documentation v1.1.1

How MCP Tools Behave

·

How tools from connected MCP servers are named, capped, confirmed and kept alive.

Tool naming

MCP-exposed tools are auto-registered with the format:

mcp__<server_name>__<tool_name>

Example: mcp__github__create_issue, mcp__sqlite-notes__read_query.

Result size cap

Each MCP tool result is capped at 1 MiB. When exceeded, the result is truncated with the marker:

[mcp output truncated: <total> bytes total, <kept> kept]

This avoids OpenAI Responses API's 10 MB single-tool-output limit triggering a same-signature retry storm. SQLite SELECT * on a large table will hit this — add LIMIT / WHERE.

Confirm behavior

MCP tools route through the most conservative defaults:

Trust is granted per tool, not per server: /mcp → server → tools (or POST /v1/allowlist with a tool block) replaces the auto-approve entries for one prefix, leaving unrelated rules alone. Every entry must start with that prefix, and prefix* collapses the rest into a whole-server grant. The list lives in ~/.config/agenvoy/allow_tool.

Lifecycle

中文