- mcpExpose=phi|direct|auto on RawConfig + MCPConfig; phi default keeps
direct as a measured option for small servers (2-tool cheaper direct)
- src/mcp.ts: buildMcpMetaTools + phi branch in connectMcp: lazy
list/inspect/call behind 3 fixed schemas instead of N per-tool schemas;
direct branch kept; bindMcpGuard wires permission+PluginHost guard for
MCP calls through the same gate as built-ins
- prompt mcpServers names-only under phi; under direct schemas travel
as before — 20-tool server ~2750 tok -> ~phi (names) until mcp_call
- session: isDirect mcpServerNames non-enumerable marker, activeTools
hides mcp_call from pre-wired rules when inside mcp_call, /tools
shows mcp_call and Enabled/Withheld reflects the 3 meta-names under phi
- permission: mcp_* as read (free), mcp_call mutating keyed by
server.tool, same top-level suppression + ask-to-approve as other
mutating tools
- cli: bindMcpGuard + /mcp list shows exposure + mcp_* listed;
headless denies line mentions mcp_list
- commit.ts: git_commit_message kept in git set via toolSetOf/
disabledToolNames overlay
Tests: 798 pass, 0 fail; tsc exit 0; mcp.test.ts covers phi stays
empty until mcp_call and direct still namespaced.