import type { RepoStack } from "../profile/scan.js"; /** * The `.mcp.json` server set is assembled from the DETECTED stack, not a fixed * boilerplate list: * - `code-review-graph` + `codebase-memory-mcp` + `sequential-thinking` (local, stdio) — * code intelligence (impact/blast radius), codebase memory (search/trace/ADR), and * structured reasoning; useful in any repo, zero egress, zero credentials; * - `github` + `context7` — on-by-default remote servers (GitHub via the client's * OAuth by default, or an env-sourced token header when requested; Context7 hosted docs). Each names its * egress in its own description so it is visible in `.mcp.json` at a glance; * - Playwright (`@playwright/mcp`) is added for a web frontend; the retired * `awslabs.core-mcp-server` is not generated for AWS repos because its * required diagram-server distribution is yanked; * - the hosted `n24q02m` toolset ONLY under `scope === "remote"` (opt-in gateway). * Every entry is configuration the client dials later — emitting it contacts nothing. */ /** * Data-handling risk class for an MCP server, surfaced in `.mcp.json` and the * remote-scope gateway doc so a reviewer can see the egress surface at a glance: * - `local` — runs as a local process (stdio); data stays on the box. * - `third-party-hosted` — an external HTTP endpoint a vendor operates; your data * leaves the machine, so it needs vendor-risk review. * Kept for back-compat and at-a-glance reading; the finer axes below * (egress / credentials / supplyChain) are what policy, drift, and the report read. */ export type McpClassification = "local" | "third-party-hosted"; /** * Where the server sends your data — the axis enterprises actually gate on: * - `none` — no network egress (pure local compute). * - `local-only` — runs locally; any network is user-directed (e.g. a browser * it drives), not a fixed backend it reports to. * - `vendor-incumbent` — a specific vendor backend orgs typically already trust * (GitHub, the user's own AWS account). * - `third-party` — a non-incumbent vendor backend; needs explicit vetting. */ export type McpEgress = "none" | "local-only" | "vendor-incumbent" | "third-party"; /** * What the server needs to authenticate — so a reviewer knows whether a secret is * involved and where it lives: * - `none` — no credential required. * - `oauth` — interactive OAuth handled by the client; NO secret is written here. * - `token` — a token / API key, sourced from env, never hardcoded into config. */ export type McpCredentials = "none" | "oauth" | "token"; /** * How the server's code is sourced — the supply-chain surface: * - `pinned` — a pinned package version launched locally (reproducible). * - `unpinned` — a floating / `@latest` launch (aih's own set never uses this). * - `hosted-remote` — code runs on the vendor's infrastructure (an HTTP endpoint). */ export type McpSupplyChain = "pinned" | "unpinned" | "hosted-remote"; /** Extra evidence for FastMCP skills-over-MCP servers exposing skill:// resources. */ export interface SkillsProviderEvidence { provider: "SkillProvider" | "SkillsProvider" | "SkillsDirectoryProvider" | "ClaudeSkillsProvider" | "skills"; serverVersion?: string; manifestSha256?: string; hotReload: boolean; } /** Risk axes every server entry carries (see the per-type docs above). */ interface McpRisk { classification: McpClassification; egress: McpEgress; credentials: McpCredentials; supplyChain: McpSupplyChain; skillsProvider?: SkillsProviderEvidence; } export interface StdioServer extends McpRisk { type: "stdio"; command: string; args: string[]; description: string; /** Process environment for the launched server. Values must be ${ENV} refs, never literals. */ env?: Readonly>; } export interface HttpServer extends McpRisk { type: "http"; url: string; description: string; /** HTTP headers for clients that support them. Values must be env refs, never literals. */ headers?: Readonly>; } export type McpServer = StdioServer | HttpServer; /** Base host for the n24q02m hosted enterprise toolset. */ export declare const N24Q02M_HOST = "n24q02m.com"; /** Hosted GitHub MCP endpoint used when no org-specific host is configured. */ export declare const DEFAULT_GITHUB_MCP_URL = "https://api.githubcopilot.com/mcp/"; export type GithubMcpAuth = "oauth" | "token"; /** Options that tune the GitHub catalog entry from committed org policy. */ export interface McpServersOptions { selfHost?: boolean; githubAuth?: GithubMcpAuth; githubHost?: string; githubIncumbent?: boolean; } /** * The exact-pinned, repository-agnostic local catalog. Profile-specific * projections select from this shared constructor instead of copying pins. */ export declare function coreLocalMcpServers(): Record; /** * Build the `mcpServers` map for `scope`, tailored to `stack`. Deterministic * insertion order (local stdio first, then stack-specific, then on-by-default * remote, then the opt-in hosted set) so golden assertions and deep-merge output * stay stable. */ export declare function mcpServers(scope: string, stack: RepoStack, opts?: McpServersOptions): Record; /** * The unique `${VAR}` names referenced by any server's `env` block — the secrets a * user must supply out-of-band. Drives `.env.example` generation so the placeholders * are documented without ever writing a value. Only `${VAR}` refs count (a literal * would be a hardcoded secret — see the `aih secrets` MCP-config scan). */ export declare function envPlaceholders(servers: Record): string[]; export {};