Tools: MCP client — เชื่อม Streamable HTTP และ guarded stdio จาก Agent TH
ENDEAVOR LOCAL AGENT TH รุ่นปัจจุบันมี generic MCP client 4 tools สำหรับเชื่อม capability ภายนอกโดยไม่ต้องเพิ่ม native tool ใหม่ทุก integration:
mcp_list_tools
mcp_call_tool
mcp_add_server
mcp_remove_server
public repo เริ่มจาก MCP_SERVERS = {} จึงไม่มี default MCP server หรือ machine-specific path ถูก hardcode มาให้ ผู้ใช้หรือ developer เป็นคนเลือกว่าต้องการเชื่อม server ใด
mcp_list_tools — ดู catalog หรือ inspect schema ก่อนเรียก
ถ้าระบุแค่ชื่อ server จะคืนรายการ tool + description แบบ compact เพื่อให้โมเดลเห็นว่า server นั้นทำอะไรได้บ้าง
ถ้าระบุ tool_name เพิ่ม จะคืน description และ inputSchema ของ tool ตัวเดียว เหมาะกับกรณีที่ Agent ต้องรู้ argument contract ที่แน่นอนก่อน call
ระบบพยายามรักษา ชื่อ tool ทุกตัว ไว้แม้ description รวมจะยาวเกิน output budget เพราะถ้าชื่อบางตัวถูกตัดทิ้ง Agent จะไม่มีทางรู้ว่าควร inspect schema ของ tool ที่ซ่อนอยู่ต่ออย่างไร
mcp_call_tool — เรียก tool โดย arguments ต้องเป็น JSON object
รับ 3 ค่า:
server
tool_name
arguments_json
arguments_json ต้อง decode เป็น JSON object เท่านั้น ถ้าเป็น list/string หรือ JSON พัง จะ fail ก่อนเปิด session
ผล text จาก MCP ถูก cap ก่อนกลับเข้า ReAct loop เพื่อไม่ให้ remote tool output ก้อนใหญ่กลืน context ทั้ง turn ส่วน policy ว่า tool ปลายทางอนุญาต action อะไรยังเป็นหน้าที่ของ MCP server นั้นเอง
mcp_add_server — เพิ่มได้ทั้ง HTTP และ stdio
มี 2 transport:
Streamable HTTP
ใส่ url และ optional headers_json
เหมาะกับ MCP endpoint ที่เปิดเป็น HTTP อยู่แล้ว โดยใช้ official MCP SDK ฝั่ง client
Local stdio
ใส่:
command— ต้องเป็น absolute executable path ที่มีอยู่จริงargs_json— JSON array ของ stringcwd— ถ้าใส่ ต้องอยู่ภายใน Agent workspace
stdio child ถูก spawn โดยไม่ผ่าน shell แล้วครอบด้วย macOS sandbox profile เดียวกับ bash
stdio MCP ไม่ได้สิทธิ์เขียนเพิ่มตามความสามารถของ tool
นี่คือ boundary สำคัญของ public fork
แม้ MCP server ที่เชื่อมจะประกาศ tool ที่ดูทรงพลัง ตัว child process ก็ยังอยู่ใต้ sandbox ปกติของ Agent TH:
- เขียนได้ใน
workspace/ - เขียนได้ใน
/tmp - sensitive read paths เดิมยังถูก deny
- ไม่มี extra write scope นอก sandbox ปกติถูกเปิดให้อัตโนมัติ
ดังนั้นการ register MCP server ไม่ใช่การเปิดทางลัดให้ child เขียน Desktop/Documents หรือ credential directories ได้อิสระ
Registry อยู่ใน workspace และเป็น private file
server ที่เพิ่มผ่าน mcp_add_server ถูกเก็บที่:
workspace/tool_mcp/servers.json
runtime ใช้:
- atomic temp-write + replace
fsync- cross-process
flock - permission
0600
เพื่อกัน torn JSON จาก concurrent mutation และลดโอกาสที่ HTTP headers ใน config จะเปิดอ่านกว้างเกินจำเป็น
workspace/ ถูก ignore จาก Git อยู่แล้ว แต่ถ้าใส่ API key ใน HTTP headers ก็ควรมองไฟล์นี้เป็น local secret-bearing runtime state และไม่ copy ไปเผยแพร่
Developer config กับ self-service registry อยู่คนละชั้น
MCP server สามารถมาจาก 2 แหล่ง:
config.MCP_SERVERS— developer provision ใน source/configworkspace/tool_mcp/servers.json— เพิ่มระหว่างใช้งานด้วยmcp_add_server
ถ้าชื่อชนกัน workspace entry จะ shadow developer entry ชั่วคราว และ mcp_remove_server ลบได้เฉพาะ self-service entry เท่านั้น เมื่อลบแล้ว developer entry เดิมจึงกลับมามีผล
behavior นี้ช่วยให้ทดลอง endpoint/config ใหม่ได้โดยไม่ต้องแก้ source ทุกครั้ง แต่ไม่เปิดให้ self-service tool ลบ configuration ที่ developer ใส่มาใน code โดยตรง
ทำไม Agent TH มี add/remove แต่ Agent Lite ไม่มี
Agent Lite จงใจมี MCP surface เล็กกว่า เพราะใช้โมเดล 2B และให้ server ถูก provision ไว้ล่วงหน้าเป็นหลัก
Agent TH เป็น agent เต็มรูปแบบสำหรับเครื่อง 24–48GB+ จึงมี generic MCP self-service 4 tools เพื่อให้เชื่อม capability ภายนอกได้ยืดหยุ่นกว่า แต่ยังเก็บ deterministic validation และ stdio sandbox ไว้ที่ code layer ไม่ได้ฝากให้โมเดล “ระวังเอง”
สรุป flow
Agent TH
│
├─ mcp_list_tools ── inspect catalog/schema
│
├─ mcp_add_server ── HTTP หรือ guarded stdio
│ │
│ └─ workspace/tool_mcp/servers.json (0600)
│
└─ mcp_call_tool ─── MCP server
│
└─ result แบบ bounded text
MCP ทำให้ Agent TH ต่อความสามารถใหม่ได้โดยไม่ต้องเพิ่ม native tool ทุก integration แต่ security boundary ของ local stdio ยังถูกยึดกับ workspace sandbox เดิม
ความคิดเห็น
กำลังโหลดความคิดเห็น...