fix(agents,hands): per-agent/per-hand mcp_servers / skills allowlists (#87) (#92)

All 32 agent manifests and 17 hands shipped with empty mcp_servers /
skills lists, which the kernel interprets as "no filter" — every
globally-configured MCP server's tools and every installed skill get
injected into the prompt on every LLM call. On a typical instance (9
MCP servers, ~85 MCP tools + ~82 built-in tools) that's ~50k input
tokens per turn spent on definitions the agent never uses.

Changes
-------

32 agents/*/agent.toml:
  - mcp_servers: 1-4 per agent. memory wherever state persists across
    turns; fetch / exa-search / brave-search only where the prompt
    actually calls for web; git / github / filesystem on engineering
    agents; gmail / google-calendar / linear / jira on productivity
    agents whose prompts mention them.
  - skills: per-role allowlist driven by what the system_prompt names
    (e.g. coder → rust/python/typescript/git/shell-scripting; devops-
    lead → docker/kubernetes/terraform/ansible/ci-cd/helm/prometheus/
    sysadmin). Generalists (assistant) keep skills = [] (see "Open
    items" below).
  - skills_disabled = true on the four short-conversational agents
    (hello-world, recipe-assistant, health-tracker, home-automation).
    Their system prompts never instruct the LLM to consult any skill,
    so loading all 60 was pure waste. They also drop the explicit
    max_history_messages override and inherit the kernel default (60).
  - max_history_messages tiered by workload shape:
      60  short conversational (hello-world, recipe, health-tracker,
          home-automation) — inherits the rising kernel default
          (`DEFAULT_MAX_HISTORY_MESSAGES = 60`); no override needed.
      60  single-turn task agents (writer, translator, doc-writer,
          email-assistant, customer-support, sales-assistant, recruit-
          er, social-media, personal-finance, tutor, travel-planner,
          meeting-assistant, ops, devops-lead, planner) — explicit
          override at the same value to lock the cap if the kernel
          default moves again.
      80  multi-step / tool-heavy (coder, debugger, architect, code-
          reviewer, test-engineer, security-auditor, analyst, data-
          scientist, academic-researcher, researcher, legal-assistant)
      120 coordinators (assistant, orchestrator) — long multi-agent
          sessions where prompt-cache continuity is critical
    All values sit at or above the kernel default. Pinning lower
    would thrash the prompt cache (the failure mode #91 fixed for
    the creator hand by *raising* the cap, not lowering it).

17 hands/*/HAND.toml:
  - hand-level mcp_servers / skills now declared on every hand, so
    every [agents.*] inside inherits a sensible allowlist.
  - skills_disabled = true placed on each [agents.*] inside clip and
    creator (pure media pipelines that don't benefit from any skill).
    HandDefinitionRaw in librefang-hands does NOT have a top-level
    skills_disabled field — declaring it at the hand top level would
    be silently dropped by serde, so the setting must live on the
    AgentManifest of each sub-agent role.
  - devteam: expand existing mcp_servers = ["github"] to include
    memory / git / filesystem; populate skills with the expected
    dev-team expertise (replacing the placeholder skills = []).
  - wiki: replace placeholder mcp_servers = [] with [memory, fetch,
    filesystem]. Hand-level skills stays [].
  - lead: hand-level skills was originally [email-writer, writing-
    coach, interview-prep]; interview-prep is for job-interview
    preparation, not lead generation. Replaced with data-analyst
    (used by the qualification-scoring step in the prompt).

schema.toml: register mcp_servers / skills / max_history_messages on
the agent field schema so machine consumers (RegistrySchema in
librefang-types) see the new top-level fields. The
max_history_messages description now points at
librefang_runtime::agent_loop::DEFAULT_MAX_HISTORY_MESSAGES (60
today) by name, so the schema doesn't go stale when the constant
moves again.

agents/README.md: example block + "Adding a New Agent" checklist
mention the allowlists; max_history_messages example is shown
commented out with a prompt-cache caveat.

Open items
----------

`assistant` (the default user-facing agent) keeps `skills = []`
deliberately. It is the generalist entry point — capping its skill
surface at a small allowlist would defeat its "delegate to any
specialist" job. The trade-off is that this single agent still pays
the full skill-definition load on every turn; operators who want a
strict allowlist for `assistant` can override it after install.

Why not adopt PR #89's approach
-------------------------------

#89 covers similar ground but with three issues this PR avoids:

1. mcp_servers = ["_none"] sentinel. #89's body explicitly notes
   it's pending upstream librefang#4808 (mcp_disabled). Shipping a
   magic-string today means coming back later to clean it up. This
   PR uses real allowlists.
2. max_history_messages = 8 / 12 / 15 / 20. Far below today's
   kernel default (60) and #91's direction for long-workflow hands
   (80–120). Every turn that hits the cap invalidates the cached
   prompt prefix; the cost of cache misses exceeds the saving from
   shorter history. This PR uses 60–120.
3. Doubling max_llm_tokens_per_hour (coder 200k→500k, assistant
   300k→500k) widens the per-agent budget — the opposite direction
   from #87's "reduce per-call cost" goal. Left to the operator's
   instance-specific tuning.

Refs librefang/librefang-registry#87, librefang/librefang-registry#89
This commit is contained in:
Evan authored and GitHub committed 2026-05-12 09:30:21 +09:00
1 parent 651ff1b34d
commit 102b506b0b
51 files changed
+462 -8

No files matched your search

+6
View File
@@ -23,6 +23,12 @@ tools = [
"event_publish",
]
# Per-hand resource allowlists (refs librefang/librefang-registry#87).
# Inherited by every [agents.*] in this hand unless overridden.
mcp_servers = ["memory", "sqlite-mcp", "postgresql", "filesystem"]
skills = ["data-analyst", "sql-analyst", "python-expert", "data-pipeline"]
[routing]
aliases = [
"data analysis",
+12
View File
@@ -24,6 +24,18 @@ tools = [
"event_publish",
]
# Per-hand resource allowlists (refs librefang/librefang-registry#87).
# Inherited by every [agents.*] in this hand unless overridden.
mcp_servers = ["memory", "github", "fetch"]
skills = [
"api-tester",
"openapi-expert",
"graphql-expert",
"python-expert",
"typescript-expert",
]
[[requires]]
key = "curl"
label = "curl must be installed"
+6
View File
@@ -28,6 +28,12 @@ tools = [
"file_read",
]
# Per-hand resource allowlists (refs librefang/librefang-registry#87).
# Inherited by every [agents.*] in this hand unless overridden.
mcp_servers = ["memory", "puppeteer"]
skills = []
[routing]
aliases = [
"open website",
+12
View File
@@ -17,6 +17,15 @@ tools = [
"memory_recall",
]
# Per-hand resource allowlists (refs librefang/librefang-registry#87).
# Inherited by every [agents.*] in this hand unless overridden.
mcp_servers = ["memory", "filesystem"]
skills = []
# `skills_disabled = true` lives on each [agents.*] below — HandDefinitionRaw
# in librefang-hands doesn't carry the field, so a hand-level entry would be
# silently dropped by serde.
[routing]
aliases = [
"clip video",
@@ -219,6 +228,7 @@ description = "AI video editor — downloads, transcribes, and creates viral sho
module = "builtin:chat"
provider = "default"
model = "default"
skills_disabled = true
max_tokens = 8192
temperature = 0.4
max_iterations = 40
@@ -622,6 +632,7 @@ description = "Content writer. Creates scripts, captions, titles, and descriptio
module = "builtin:chat"
provider = "default"
model = "default"
skills_disabled = true
max_tokens = 4096
temperature = 0.7
system_prompt = """You are Writer, a short-form video content specialist within the Clip Hand.
@@ -760,6 +771,7 @@ description = "Social media strategist. Plans distribution, scheduling, and enga
module = "builtin:chat"
provider = "default"
model = "default"
skills_disabled = true
max_tokens = 4096
temperature = 0.7
system_prompt = """You are Distributor, the publishing and distribution specialist within the Clip Hand.
+6
View File
@@ -25,6 +25,12 @@ tools = [
"event_publish",
]
# Per-hand resource allowlists (refs librefang/librefang-registry#87).
# Inherited by every [agents.*] in this hand unless overridden.
mcp_servers = ["memory", "fetch", "exa-search", "brave-search", "filesystem"]
skills = ["data-analyst"]
[routing]
aliases = [
"monitor changes",
+11
View File
@@ -20,6 +20,15 @@ tools = [
"memory_recall",
]
# Per-hand resource allowlists (refs librefang/librefang-registry#87).
# Inherited by every [agents.*] in this hand unless overridden.
mcp_servers = ["memory", "filesystem"]
skills = []
# `skills_disabled = true` lives on each [agents.*] below — HandDefinitionRaw
# in librefang-hands doesn't carry the field, so a hand-level entry would be
# silently dropped by serde.
[routing]
aliases = [
"generate image",
@@ -172,6 +181,7 @@ description = "AI media studio — generates images, videos, music, and speech f
module = "builtin:chat"
provider = "default"
model = "default"
skills_disabled = true
max_tokens = 8192
temperature = 0.5
max_iterations = 30
@@ -279,6 +289,7 @@ description = "Prompt engineer that crafts detailed, effective prompts for media
module = "builtin:chat"
provider = "default"
model = "default"
skills_disabled = true
max_tokens = 4096
temperature = 0.8
system_prompt = """You are Prompt Writer, a creative prompt engineer within the Creator Hand.
+24
View File
@@ -24,6 +24,30 @@ tools = [
"event_publish",
]
# Per-hand resource allowlists (refs librefang/librefang-registry#87).
# Inherited by every [agents.*] in this hand unless overridden.
mcp_servers = [
"memory",
"git",
"github",
"filesystem",
"sentry",
"elasticsearch",
]
skills = [
"docker",
"kubernetes",
"terraform",
"ansible",
"ci-cd",
"helm",
"prometheus",
"sysadmin",
"linux-networking",
"shell-scripting",
]
[[requires]]
key = "curl"
label = "curl must be installed"
+13 -4
View File
@@ -30,11 +30,20 @@ tools = [
"workflow_run",
]
# MCP servers: all agents can access these (per-agent mcp_servers further restricts)
mcp_servers = ["github"]
# Per-hand resource allowlists (refs librefang/librefang-registry#87).
# Inherited by every [agents.*] in this hand unless overridden.
mcp_servers = ["memory", "github", "git", "filesystem"]
skills = [
"github",
"git-expert",
"rust-expert",
"python-expert",
"typescript-expert",
"code-reviewer",
"api-tester",
"ci-cd",
]
# Skills: all available (agents can restrict individually)
skills = []
# Plugins: useful for dev workflow
allowed_plugins = ["todo-tracker", "auto-summarizer", "episodic-memory"]
+13
View File
@@ -24,6 +24,19 @@ tools = [
"knowledge_query",
]
# Per-hand resource allowlists (refs librefang/librefang-registry#87).
# Inherited by every [agents.*] in this hand unless overridden.
mcp_servers = [
"memory",
"fetch",
"gmail",
"linear",
"exa-search",
"brave-search",
]
skills = ["email-writer", "writing-coach", "data-analyst"]
[routing]
aliases = [
"lead generation",
+6
View File
@@ -23,6 +23,12 @@ tools = [
"event_publish",
]
# Per-hand resource allowlists (refs librefang/librefang-registry#87).
# Inherited by every [agents.*] in this hand unless overridden.
mcp_servers = ["memory", "fetch"]
skills = ["writing-coach", "email-writer"]
[routing]
aliases = ["linkedin", "profile optimization", "professional networking"]
weak_aliases = ["professional engagement", "linkedin post"]
+6
View File
@@ -23,6 +23,12 @@ tools = [
"knowledge_query",
]
# Per-hand resource allowlists (refs librefang/librefang-registry#87).
# Inherited by every [agents.*] in this hand unless overridden.
mcp_servers = ["memory", "fetch", "exa-search", "brave-search"]
skills = ["data-analyst", "python-expert"]
[routing]
aliases = [
"predict",
+6
View File
@@ -23,6 +23,12 @@ tools = [
"event_publish",
]
# Per-hand resource allowlists (refs librefang/librefang-registry#87).
# Inherited by every [agents.*] in this hand unless overridden.
mcp_servers = ["memory", "fetch"]
skills = ["writing-coach"]
[routing]
aliases = ["reddit", "subreddit", "reddit post", "reddit monitor"]
weak_aliases = ["karma", "reddit thread"]
+6
View File
@@ -26,6 +26,12 @@ tools = [
"event_publish",
]
# Per-hand resource allowlists (refs librefang/librefang-registry#87).
# Inherited by every [agents.*] in this hand unless overridden.
mcp_servers = ["memory", "fetch", "exa-search", "brave-search"]
skills = ["technical-writer", "writing-coach", "python-expert", "pdf-reader"]
[routing]
aliases = [
"deep research",
+6
View File
@@ -24,6 +24,12 @@ tools = [
"event_publish",
]
# Per-hand resource allowlists (refs librefang/librefang-registry#87).
# Inherited by every [agents.*] in this hand unless overridden.
mcp_servers = ["memory", "fetch", "exa-search", "brave-search"]
skills = ["project-manager", "data-analyst", "writing-coach"]
[routing]
aliases = [
"strategic analysis",
+6
View File
@@ -25,6 +25,12 @@ tools = [
"event_publish",
]
# Per-hand resource allowlists (refs librefang/librefang-registry#87).
# Inherited by every [agents.*] in this hand unless overridden.
mcp_servers = ["memory", "fetch", "postgresql", "sqlite-mcp"]
skills = ["data-analyst", "sql-analyst", "python-expert"]
[routing]
aliases = [
"trade",
+6
View File
@@ -24,6 +24,12 @@ tools = [
"event_publish",
]
# Per-hand resource allowlists (refs librefang/librefang-registry#87).
# Inherited by every [agents.*] in this hand unless overridden.
mcp_servers = ["memory", "fetch"]
skills = ["writing-coach"]
[routing]
aliases = [
"twitter",
+5 -1
View File
@@ -18,8 +18,12 @@ tools = [
"memory_store",
]
mcp_servers = []
# Per-hand resource allowlists (refs librefang/librefang-registry#87).
# Inherited by every [agents.*] in this hand unless overridden.
mcp_servers = ["memory", "fetch", "filesystem"]
skills = []
allowed_plugins = []
# memory_store is used ONLY for dashboard metrics.
# No wiki content enters LibreFang's general memory — all knowledge lives in the vault.