SIGN IN SIGN UP

Give Guardian trusted context for configured MCP tools (#40982)

## What changed

- Add a bounded developer context fragment identifying the MCP server or connector and the user-owned configuration that declared it.
- Emit the fragment only when the effective entry matches the user configuration or an active plugin declaration resolves inside the Codex home directory.
- Keep tool descriptions, outputs, and unrelated tools untrusted, and reject unsupported sources or paths that escape through symlinks.

## Testing

- Cover user-configured servers and connectors, plugin-provided capabilities, token truncation, symlink escapes, and app-server request integration.

GitOrigin-RevId: 0bfe2a2f3a48334d1d5faad692b5d36452febb68
F
felixxia-oai committed
d61ba72f2f8af9adb694b8701aa64ed96cd80760
Parent: 07d260c
Committed by copyberry <copyberry@app.openai.com> on 8/26/2026, 9:48:05 PM