mcp_redact_secrets() throws "subscript out of bounds" on schemas containing a null field
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 88/100
Hướng nghiên cứu
Bắt đầu trong R/client.R tại mcp_redact_secrets() và chạy bản tái hiện schema được cung cấp để quan sát lỗi subscript. Xác minh rằng các phản hồi chứa các trường schema có giá trị null không còn bị lỗi, trong khi các trường bí mật vẫn được redacted trước khi ghi nhật ký debug của client.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Bug
mcp_tools() fails with subscript out of bounds while loading tools from a remote MCP server, inside add_mcp_server() / mcp_redact_secrets().
Root cause
mcp_redact_secrets() (R/client.R) is called unconditionally on every MCP server response, purely to redact secrets before writing to the client debug log (MCPTOOLS_CLIENT_LOG). It iterates for (i in seq_along(x)) while mutating x in place. When a field's JSON value is null (parsed by jsonlite::parse_json() as R NULL), the assignment x[[i]] <- NULL deletes that list element and shrinks x, so later iterations of the same loop index past the new, shorter length.
Trigger
Any MCP server that returns a tool schema containing a null-valued field anywhere in the response will hit this. Concretely, I hit it against the Google Analytics MCP server: its run_report, run_realtime_report, and run_conversions_report tools each expose a dimension_filter / metric_filter parameter whose JSON Schema legitimately includes "default": null - a completely valid, spec-compliant schema.
Repro
schema <- list(
additionalProperties = TRUE,
default = NULL,
title = "Dimension Filter",
type = "object"
)
# Reproduces the mutate-while-iterating bug directly:
mcptools:::mcp_redact_secrets(list(params = list(dimension_filter = schema)))
# Error in x[[i]] : subscript out of bounds
More generally, calling mcp_tools(config = ...) against any remote server whose tools/list response includes such a schema fails the same way.
Suggested fix
Build the redacted list into a fresh vector("list", length(x)) instead of mutating x in place, so a NULL assignment can't change the list's length mid-loop:
mcp_redact_secrets <- function(x) {
if (!is.list(x)) return(x)
nms <- names(x)
if (is.null(nms)) {
return(lapply(x, mcp_redact_secrets))
}
secret_fields <- mcp_secret_fields()
out <- vector("list", length(x))
for (i in seq_along(x)) {
name <- tolower(nms[[i]])
if (nzchar(name) && name %in% secret_fields) {
out[[i]] <- "<redacted>"
} else {
out[[i]] <- mcp_redact_secrets(x[[i]])
}
}
names(out) <- nms
out
}
Environment
mcptools1.0.3.9000 (installed from GitHub)- Confirmed the same unpatched loop is present in
R/client.Ron themainbranch as of 2026-09-29, so this isn't fixed in a newer release yet. - R 4.4.3, Windows
Workaround in use
We're currently monkey-patching mcp_redact_secrets in-process at app startup (via assignInNamespace-style unlockBinding()/assign()/lockBinding()) with the fixed implementation above, as a stopgap until this is fixed upstream.
- Ngôn ngữ chính
- R
- Star
- 198
- Fork
- 23
- Merge trung bình
- 10 ngày 21 giờ
- Pull request đã merge (30 ngày)
- 1
Chuẩn bị môi trường
Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của posit-dev/mcptools
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 55/100
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
Tất cả issue của posit-dev/mcptools
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
Maintainer thường phản hồi trong vòng 3 ngày
-
Elevation orderĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
inbo/erl-butterflies-2025#19 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
-
Component: R good-first-issue Type: enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
The-Strategy-Unit/nhp_output_reports#116 · 1 bình luận ·