Evan 102b506b0b fix(agents,hands): per-agent/per-hand mcp_servers / skills allowlists (#87) (#92)
All 32 agent manifests and 17 hands shipped with empty mcp_servers /
skills lists, which the kernel interprets as "no filter" — every
globally-configured MCP server's tools and every installed skill get
injected into the prompt on every LLM call. On a typical instance (9
MCP servers, ~85 MCP tools + ~82 built-in tools) that's ~50k input
tokens per turn spent on definitions the agent never uses.

Changes
-------

32 agents/*/agent.toml:
  - mcp_servers: 1-4 per agent. memory wherever state persists across
    turns; fetch / exa-search / brave-search only where the prompt
    actually calls for web; git / github / filesystem on engineering
    agents; gmail / google-calendar / linear / jira on productivity
    agents whose prompts mention them.
  - skills: per-role allowlist driven by what the system_prompt names
    (e.g. coder → rust/python/typescript/git/shell-scripting; devops-
    lead → docker/kubernetes/terraform/ansible/ci-cd/helm/prometheus/
    sysadmin). Generalists (assistant) keep skills = [] (see "Open
    items" below).
  - skills_disabled = true on the four short-conversational agents
    (hello-world, recipe-assistant, health-tracker, home-automation).
    Their system prompts never instruct the LLM to consult any skill,
    so loading all 60 was pure waste. They also drop the explicit
    max_history_messages override and inherit the kernel default (60).
  - max_history_messages tiered by workload shape:
      60  short conversational (hello-world, recipe, health-tracker,
          home-automation) — inherits the rising kernel default
          (`DEFAULT_MAX_HISTORY_MESSAGES = 60`); no override needed.
      60  single-turn task agents (writer, translator, doc-writer,
          email-assistant, customer-support, sales-assistant, recruit-
          er, social-media, personal-finance, tutor, travel-planner,
          meeting-assistant, ops, devops-lead, planner) — explicit
          override at the same value to lock the cap if the kernel
          default moves again.
      80  multi-step / tool-heavy (coder, debugger, architect, code-
          reviewer, test-engineer, security-auditor, analyst, data-
          scientist, academic-researcher, researcher, legal-assistant)
      120 coordinators (assistant, orchestrator) — long multi-agent
          sessions where prompt-cache continuity is critical
    All values sit at or above the kernel default. Pinning lower
    would thrash the prompt cache (the failure mode #91 fixed for
    the creator hand by *raising* the cap, not lowering it).

17 hands/*/HAND.toml:
  - hand-level mcp_servers / skills now declared on every hand, so
    every [agents.*] inside inherits a sensible allowlist.
  - skills_disabled = true placed on each [agents.*] inside clip and
    creator (pure media pipelines that don't benefit from any skill).
    HandDefinitionRaw in librefang-hands does NOT have a top-level
    skills_disabled field — declaring it at the hand top level would
    be silently dropped by serde, so the setting must live on the
    AgentManifest of each sub-agent role.
  - devteam: expand existing mcp_servers = ["github"] to include
    memory / git / filesystem; populate skills with the expected
    dev-team expertise (replacing the placeholder skills = []).
  - wiki: replace placeholder mcp_servers = [] with [memory, fetch,
    filesystem]. Hand-level skills stays [].
  - lead: hand-level skills was originally [email-writer, writing-
    coach, interview-prep]; interview-prep is for job-interview
    preparation, not lead generation. Replaced with data-analyst
    (used by the qualification-scoring step in the prompt).

schema.toml: register mcp_servers / skills / max_history_messages on
the agent field schema so machine consumers (RegistrySchema in
librefang-types) see the new top-level fields. The
max_history_messages description now points at
librefang_runtime::agent_loop::DEFAULT_MAX_HISTORY_MESSAGES (60
today) by name, so the schema doesn't go stale when the constant
moves again.

agents/README.md: example block + "Adding a New Agent" checklist
mention the allowlists; max_history_messages example is shown
commented out with a prompt-cache caveat.

Open items
----------

`assistant` (the default user-facing agent) keeps `skills = []`
deliberately. It is the generalist entry point — capping its skill
surface at a small allowlist would defeat its "delegate to any
specialist" job. The trade-off is that this single agent still pays
the full skill-definition load on every turn; operators who want a
strict allowlist for `assistant` can override it after install.

Why not adopt PR #89's approach
-------------------------------

#89 covers similar ground but with three issues this PR avoids:

1. mcp_servers = ["_none"] sentinel. #89's body explicitly notes
   it's pending upstream librefang#4808 (mcp_disabled). Shipping a
   magic-string today means coming back later to clean it up. This
   PR uses real allowlists.
2. max_history_messages = 8 / 12 / 15 / 20. Far below today's
   kernel default (60) and #91's direction for long-workflow hands
   (80–120). Every turn that hits the cap invalidates the cached
   prompt prefix; the cost of cache misses exceeds the saving from
   shorter history. This PR uses 60–120.
3. Doubling max_llm_tokens_per_hour (coder 200k→500k, assistant
   300k→500k) widens the per-agent budget — the opposite direction
   from #87's "reduce per-call cost" goal. Left to the operator's
   instance-specific tuning.

Refs librefang/librefang-registry#87, librefang/librefang-registry#89
2026-05-12 09:30:21 +09:00

LibreFang Registry

Community-maintained content registry for LibreFang — the open-source Agent Operating System.

This repository is the single source of truth for all installable content definitions. Anyone can submit a PR to add new agents, hands, MCP servers, skills, or provider models — no changes to the LibreFang binary required.

Overview

Type Count Description
Hands 14 User-facing "apps" — agent + tools + settings + dashboard
Agents 32 Autonomous agent definitions with model config and tools
MCP Servers 25 MCP server connections (GitHub, Slack, DBs, etc.)
Providers 46 LLM provider & model metadata with pricing
Models 232 Individual model definitions across all providers
Aliases 70 Short names mapped to canonical model IDs
Plugins 10 Memory, guardrails, and conversation plugins
Skills 2 Reusable prompt templates and Python scripts
Workflows 9 Pre-built multi-agent workflow definitions
Templates 6 Starter templates for each content type

Repository Structure

librefang-registry/
├── agents/                # Agent definitions (TOML manifests)
│   ├── hello-world/
│   │   └── agent.toml
│   ├── researcher/
│   │   └── agent.toml
│   └── ...                (32 agents)
├── hands/                 # Hand definitions (app bundles)
│   ├── browser/
│   │   ├── HAND.toml      # Metadata, tools, settings, i18n (6 languages)
│   │   └── SKILL.md       # Domain expert knowledge injected at runtime
│   ├── trader/
│   │   ├── HAND.toml
│   │   └── SKILL.md
│   └── ...                (14 hands)
├── mcp/                   # MCP server templates
│   ├── github.toml
│   ├── slack.toml
│   └── ...                (25 MCP servers)
├── providers/             # LLM provider & model metadata
│   ├── anthropic.toml
│   ├── openai.toml
│   └── ...                (46 providers, 232 models)
├── plugins/               # Memory, guardrails, and utility plugins
│   ├── episodic-memory/
│   ├── guardrails/
│   └── ...                (10 plugins)
├── skills/                # Reusable skill definitions
│   ├── custom-skill-prompt/skill.toml
│   └── custom-skill-python/
├── workflows/             # Pre-built multi-agent workflow definitions
│   ├── code-review.toml
│   ├── research.toml
│   └── ...                (9 workflows)
├── templates/             # Starter templates for each content type
│   ├── agent.toml
│   ├── HAND.toml
│   └── ...                (6 templates)
├── docs/                  # Additional documentation
│   └── content-guide.md   # Content contribution guidelines
├── aliases.toml           # Global model alias mappings (70 aliases)
├── schema.toml            # Provider/model schema reference
├── scripts/
│   └── validate.py        # Content validation script
├── CONTRIBUTING.md
└── LICENSE                # MIT

Content Types

Hands

Hands are the user-facing "apps" in LibreFang. Each hand bundles an agent, tools, user-configurable settings, dashboard metrics, dependency checks, and i18n translations into a single deployable unit.

Every hand includes a SKILL.md — domain-specific expert knowledge that is injected into the agent's context at runtime, giving it deep expertise in its domain.

Icon Hand Category Description
📈 analytics data Data collection, analysis, visualization, dashboards, and automated reporting
🔌 apitester development Endpoint discovery, request validation, load testing, and regression detection
🌐 browser productivity Web navigation, form filling, and multi-step web tasks with user approval
🎬 clip content Turns long-form video into viral short clips with captions and thumbnails
🔍 collector data Intelligence collection, change detection, and knowledge graphs
👷 devops development CI/CD management, infrastructure monitoring, deployment, and incident response
📊 lead data Lead generation, enrichment, scoring, and scheduled delivery
💼 linkedin communication Profile optimization, content creation, networking, and engagement
🔮 predictor data Signal collection, calibrated predictions, and accuracy tracking
📢 reddit communication Subreddit monitoring, content posting, and engagement tracking
🧪 researcher productivity Deep research, cross-referencing, fact-checking, and structured reports
🎯 strategist productivity Market research, competitive analysis, and strategic planning
📈 trader data Multi-signal analysis, adversarial reasoning, and risk management
𝕏 twitter communication Content creation, scheduled posting, engagement, and analytics

HAND.toml format:

id = "browser"
name = "Browser Hand"
description = "Autonomous web browser"
category = "productivity"
icon = "🌐"
tools = ["browser_navigate", "browser_click", "browser_type"]

[routing]
aliases = ["browse", "open website"]
weak_aliases = ["web", "url"]

[[requires]]
key = "chromium"
requirement_type = "binary"
check_value = "chromium"

[[settings]]
key = "headless"
setting_type = "toggle"
default = "true"

[agent]
name = "browser-hand"
module = "builtin:chat"
system_prompt = """You are an autonomous web browser agent..."""

[dashboard]
[[dashboard.metrics]]
label = "Pages Visited"
memory_key = "pages_visited"
format = "number"

# i18n — 6 languages supported: zh, ja, ko, es, fr, de
[i18n.zh]
name = "浏览器 Hand"
description = "自主网页浏览器"
category = "生产力"

[i18n.zh.settings.headless]
label = "无头模式"
description = "在后台运行浏览器"

Agents

Agent definitions describe autonomous agents with model configuration, tools, capabilities, and routing aliases.

name = "hello-world"
description = "A friendly greeting agent"
module = "builtin:chat"

[model]
provider = "default"
model = "default"
system_prompt = "You are a helpful assistant."

[capabilities]
tools = ["web_search", "file_read"]

32 built-in agents: academic-researcher, analyst, architect, assistant, code-reviewer, coder, customer-support, data-scientist, debugger, devops-lead, doc-writer, email-assistant, health-tracker, hello-world, home-automation, legal-assistant, meeting-assistant, ops, orchestrator, personal-finance, planner, recipe-assistant, recruiter, researcher, sales-assistant, security-auditor, social-media, test-engineer, translator, travel-planner, tutor, writer

MCP Servers

MCP server templates define MCP server connections with transport configuration, required environment variables, and setup instructions.

id = "github"
name = "GitHub"
category = "devtools"

[transport]
type = "stdio"
command = "npx"
args = ["-y", "@modelcontextprotocol/server-github"]

[[required_env]]
name = "GITHUB_PERSONAL_ACCESS_TOKEN"
is_secret = true

25 MCP servers across 6 categories:

Category MCP Servers
DevTools bitbucket, github, gitlab, jira, linear, sentry
Data elasticsearch, mongodb, postgresql, redis, sqlite
Productivity dropbox, gmail, google-calendar, google-drive, notion, todoist
Communication discord, slack, teams
Cloud aws, azure, gcp
AI Search brave-search, exa-search

Providers

Provider files define LLM providers and their models with pricing, context windows, and capability flags. See schema.toml for the full field reference.

49 providers including: Anthropic, OpenAI, Google Gemini, DeepSeek, Groq, Mistral, Cohere, xAI, Together, Fireworks, Ollama (local), LM Studio (local), vLLM (self-hosted), Alibaba Coding Plan, and many more.

339 models with metadata for each: pricing (input/output per token), context window size, capability flags (vision, function calling, streaming), and tier classification.

Aliases

Global model alias mappings in aliases.toml let users reference models by short names:

"sonnet" = "claude-sonnet-4-6"
"gpt4" = "gpt-4o"
"flash" = "gemini-2.5-flash"
"deepseek" = "deepseek-chat"

Models can also define aliases directly in their provider TOML files, which are auto-registered at load time.

Plugins

Plugins extend agent capabilities with memory systems, safety guardrails, and conversation utilities.

10 plugins: auto-summarizer, context-decay, conversation-logger, episodic-memory, guardrails, keyword-memory, sentiment-tracker, todo-tracker, topic-memory, user-profile

Skills

Reusable prompt templates or Python scripts that agents can invoke.

[skill]
name = "meeting-agenda"
description = "Generate a structured meeting agenda"

[runtime]
type = "promptonly"

[prompt]
template = "Create a meeting agenda for: {{topic}}"

Workflows

Pre-built multi-agent workflow definitions in workflows/<name>.toml orchestrate multiple agents for complex tasks.

9 workflows: brainstorm, code-review, content-pipeline, content-review, customer-support, data-pipeline, research, translate-polish, weekly-report

Templates

Starter templates in templates/ for creating new content. Copy a template to get started quickly:

cp templates/agent.toml agents/my-agent/agent.toml
cp templates/HAND.toml hands/my-hand/HAND.toml

6 templates: agent.toml, HAND.toml, integration.toml, plugin.toml, provider.toml, skill.toml

See also docs/content-guide.md for naming conventions and contribution guidelines.

Usage

Install from Registry

# Update all registry content
librefang catalog update

# Install a specific hand
librefang hand install browser

# Install a specific MCP server
librefang mcp install github

Custom Local Content

Create custom content locally without submitting to this registry:

# Custom agent
mkdir -p ~/.librefang/agents/my-agent
# Edit ~/.librefang/agents/my-agent/agent.toml

# Custom model aliases
# Add to ~/.librefang/model_catalog.toml

Validation

python scripts/validate.py

Validates all content files for correctness: required fields, valid types, non-negative costs, no duplicate IDs.

Contributing

  1. Fork this repository
  2. Add or edit content in the appropriate directory
  3. Run validation: python scripts/validate.py
  4. Submit a Pull Request

See CONTRIBUTING.md for detailed instructions for each content type.

License

MIT License. See LICENSE.

S
Description
Arka mirror of the LibreFang community content registry — agents, hands, integrations, skills, and provider models. Mirrored from github.com/librefang/librefang-registry.
Readme MIT
1.7 MiB
0 Stars 1 Watchers 0 Forks
Languages
Python 88.5%
JavaScript 7.6%
Makefile 3.6%
Shell 0.3%