Conversation
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: TanStack/ai/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (9)
Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review. 📝 WalkthroughWalkthroughThe MCP client now exposes instructions received during the server handshake. Unit and end-to-end tests check the provided and absent cases. Documentation describes adding the instructions to ChangesMCP server instructions
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Feature Suggested reviewers: Merge Risk: ⚪ Minimal · up to The optional client field exposes server instructions to hosts, with coverage for their presence, absence, and HTTP delivery. No actionable merge-blocking risk is established; normal checks remain appropriate. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The API change is additive and does not automatically inject instructions into chats. However, the documented example gives the selected MCP server system-prompt influence. Applications following it must trust that server for this purpose; any downstream effect depends on the conversation data and tools the application permits. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 5 files. (4 skipped: 4 unsupported.)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Thanks for the PR, @pltoledo! 🙌 @tombeckenham will take a look. Automated pre-review checks
Automated triage — a human review follows. |
An
MCPClientnow hasinstructions. It holds the text the server sends when the client connects, so a host can put it in the system prompt. The MCP spec defines these instructions for that use. Before this PR the SDKClientwas private, so a host could not read them.🎯 Changes
MCPClient.instructions?: string.MCPClientImplsets it after connect, next tocapabilities, from the SDKgetInstructions(). The SDK fills it for the 2025 initialize handshake and for spec 2026 discover.MCPClientobject (tests and user code have them) keeps compiling.getInfo().clientOptionsuses the same rule.MCPClientsdoes not change.pool.clients.<key>.instructionsalready gives the value for each server.docs/tools/mcp-manual.md, aupdatedAtbump indocs/config.json, and two lines in theai-mcppackage skill.@tanstack/ai-mcp.✅ Checklist
pnpm run test:pr, or these tests do not apply to this pull request.docs/for this change, or this change is not user-facing.pnpm changeset), or this PR does not change a published package.🚀 Release Impact
Testing
Commands run:
pnpm test:pr: pass (sherif, knip, docs, kiira, oxlint, lib, types, build).pnpm exec playwright test tests/mcp.spec.ts tests/mcp-typed.spec.ts tests/mcp-lifecycle.spec.tsintesting/e2e: 9 passed. The full E2E matrix was not run locally.Manual test:
pnpm --filter @tanstack/ai-mcp test:lib -- tests/client.test.ts.testing/e2e, runpnpm exec playwright test tests/mcp.spec.ts -g instructions.Tests on this branch:
client.test.tschecks the instructions from a test server, andundefinedwhen the server sends none.api.mcp-server.tsnow sends instructions. A newGET /api/mcp-testreturnsmcp.instructions, andmcp.spec.tschecks the value over HTTP.Risk / rollback
Low. The change adds one optional read-only field. Revert the PR to undo it.
Public API change
Before
After
Summary by CodeRabbit
New Features
Tests