MCP tool names are user-controlled (server config) and may leak filepaths. * Collapse them to 'mcp'; built-in names are a fixed vocabulary.
(name: string)
| 181 | /** MCP tool names are user-controlled (server config) and may leak filepaths. |
| 182 | * Collapse them to 'mcp'; built-in names are a fixed vocabulary. */ |
| 183 | function sanitizeToolName(name: string): string { |
| 184 | return name.startsWith('mcp__') ? 'mcp' : name |
| 185 | } |
| 186 | |
| 187 | function computePerToolHashes( |
| 188 | strippedTools: ReadonlyArray<unknown>, |
nothing calls this directly
no outgoing calls
no test coverage detected