Give Guardian trusted context for configured MCP tools (#40982)
## What changed - Add a bounded developer context fragment identifying the MCP server or connector and the user-owned configuration that declared it. - Emit the fragment only when the effective entry matches the user configuration or an active plugin declaration resolves inside the Codex home directory. - Keep tool descriptions, outputs, and unrelated tools untrusted, and reject unsupported sources or paths that escape through symlinks. ## Testing - Cover user-configured servers and connectors, plugin-provided capabilities, token truncation, symlink escapes, and app-server request integration. GitOrigin-RevId: 0bfe2a2f3a48334d1d5faad692b5d36452febb68
F
felixxia-oai committed
d61ba72f2f8af9adb694b8701aa64ed96cd80760
Parent: 07d260c
Committed by copyberry <copyberry@app.openai.com>
on 8/26/2026, 9:48:05 PM