[BUG] MCP clients get no tools from v0.3.0: kubescape_get_vulnerability_details outputSchema is not an object
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 82/100
Hướng nghiên cứu
Bắt đầu với pkg/kubescape/kubescape.go và kiểu đầu ra của handleGetVulnerabilityDetails, sau đó đọc cmd/tools_output_schema_test.go và bài kiểm thử TestEveryToolHasValidOutputSchema. Bọc đầu ra slice trong một object như mô tả, đồng thời củng cố bài kiểm thử để yêu cầu kiểu schema đầu ra của mọi công cụ là object. Hoàn tất khi bài kiểm thử schema chạy thành công và phát hiện các schema không phải kiểu object.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Bug · Severity: Medium · default install · no workaround short of disabling the Kubescape tools
Affects: kagent-tools v0.3.0 (bundled with kagent v0.10.3) · Component: MCP server, tools/list
Introduced by: #66 "Migrate to GO SDK" (merged 2026-09-23)
What breaks
As a user I point an MCP client (MCP Inspector, VS Code, Cursor, Claude Desktop, anything on the TypeScript SDK) at the kagent-tools server. On v0.2.1 the client lists all 124 tools. On v0.3.0, which serves 126, I get none: one tool advertises an invalid outputSchema, and the client rejects the entire tools/list response.
Failed to list tools: [{"code":"invalid_value","values":["object"],
"path":["tools",113,"outputSchema","type"],"message":"Invalid input: expected \"object\""}]
Tool 113 is kubescape_get_vulnerability_details. Its outputSchema is {"type": ["null","array"]}. The MCP spec (2025-06-18) requires a tool's outputSchema to have type: "object", because structured content is always a JSON object.
Reproduce
Docker only, no cluster needed:
docker run -d --name kt --platform linux/amd64 -p 18084:8084 ghcr.io/kagent-dev/kagent/tools:0.3.0 --port 8084
npx @modelcontextprotocol/[email protected] --cli http://localhost:18084/mcp --transport http --method tools/list
The same command against ghcr.io/kagent-dev/kagent/tools:0.2.1 lists all 124 tools and exits 0.
Expected vs actual
- Expected: every tool's
outputSchemais an object schema, andtools/listsucceeds on spec-compliant clients. - Actual:
kubescape_get_vulnerability_detailsadvertises an array schema, and strict clients get no tools at all.
Ask
Wrap that tool's output in an object, and make the existing schema test enforce type: "object" so the next slice-returning handler can't regress it. It's a one-type change. Clients stay broken until a release ships it.
Root cause: the handler's typed output is a slice, so go-sdk infers an array schema
pkg/kubescape/kubescape.go (v0.3.0, unchanged on main):
func (k *KubescapeTool) handleGetVulnerabilityDetails(ctx context.Context, request *sdkmcp.CallToolRequest,
in getVulnerabilityDetailsInput) (*sdkmcp.CallToolResult, []v1beta1.Match, error)
go-sdk (v1.8.0) infers the output schema from the Out type parameter. A nil-able slice becomes {"type":["null","array"]}.
Suggested fix:
type vulnerabilityDetailsOutput struct {
Matches []v1beta1.Match `json:"matches"`
}
cmd/tools_output_schema_test.go (TestEveryToolHasValidOutputSchema) only checks that each schema is non-nil and JSON-serializable, so this passed CI. Adding require.Equal(t, "object", tool.OutputSchema.(map[string]any)["type"]) (or the equivalent on the typed schema) would catch it.
Scope: exactly one of 126 tools is affected, and the server itself works
Raw JSON-RPC against the v0.3.0 image, with no client-side validation, lists every tool whose schema isn't an object:
H='-H Content-Type:application/json -H Accept:application/json,text/event-stream'
SID=$(curl -s -D - -o /dev/null $H http://localhost:18084/mcp \
-d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"t","version":"1"}}}' \
| awk -F': ' 'tolower($1)=="mcp-session-id"{print $2}' | tr -d '\r')
curl -s $H -H "Mcp-Session-Id: $SID" http://localhost:18084/mcp -d '{"jsonrpc":"2.0","method":"notifications/initialized"}'
curl -s $H -H "Mcp-Session-Id: $SID" -H "MCP-Protocol-Version: 2025-06-18" http://localhost:18084/mcp \
-d '{"jsonrpc":"2.0","id":2,"method":"tools/list"}' | sed -n 's/^data: //p' \
| jq -c '.result.tools|to_entries[]|select(.value.outputSchema.type!="object")|{i:.key,name:.value.name,type:.value.outputSchema.type}'
# {"i":113,"name":"kubescape_get_vulnerability_details","type":["null","array"]}
- Reproduced with image digest
sha256:cb89eb76216195a90cac73846b447525b6e6e33e45154d1ded9621bf11340315, both locally and in a kind cluster running kagentv0.10.3. The0.2.1image, run the same way, passes with 124 tools. - Not a client-version artifact: the image is the only thing that changed between a passing and a failing run (kagent v0.10.2 → v0.10.3, kagent-tools 0.2.1 → 0.3.0). The Inspector version was pinned at 0.21.2 in both.
- Not affected: kagent agents themselves. Their MCP clients don't validate
outputSchema.type, so the RemoteMCPServer staysAcceptedand agents still call tools. Only strict, spec-validating clients break.
- Ngôn ngữ chính
- Go
- Star
- 36
- Fork
- 29
- Merge trung bình
- 3 ngày 23 giờ
- Pull request đã merge (30 ngày)
- 3
Chuẩn bị môi trường
Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.
- Có Dockerfile hoặc tệp Docker Compose
- Không có mẫu pull request
- Không có hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của kagent-dev/tools
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
kagent-dev/tools#54 ·
-
[FEATURE] Add a limit parameter to k8s_get_resources to bound context growthCó thể đã có người làm @anjosluc đã nhận 21 ngày trước. Đang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 45/100
kagent-dev/tools#82 ·
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 78/100
kagent-dev/tools#80 ·
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 72/100
kagent-dev/tools#69 · 1 bình luận ·
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 68/100
kagent-dev/tools#68 · 1 bình luận ·
Tất cả issue của kagent-dev/tools
Issue tương tự
-
automation models
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Bug pulumi/pulumi
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
stripe/stripe-cli#2130 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Linux notifications: the default action's ' ' label shows as a blank button in xfce4-notifydĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
kovidgoyal/kitty#10625 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 6 ngày