Watch
0
0
Fork
You've already forked hyperhive
0

remove the create_repo agent tool

mara ruled on #4849 (c88934): "remove create_repo tool". The tool ran in
hive-c0re with the hive's core token, so it only ever worked for agents
on the hive that runs the forge.

Removed:

- the create_repo MCP tool and CreateRepoArgs (hive-agent-mcp)
- wire variants Request::CreateRepo and Response::RepoCreated
  (hive-core-agent-sock)
- hive-c0re's handle_create_repo, its valid_repo_name check and the
  dispatch arm
- forge::create_agent_repo and apply_operator_branch_protection, which
  had no other caller, plus AGENTS_ORG and OPERATORS_TEAM, whose only
  users they were
- the tool's docs (docs/tools/forge.md repo management, docs/turn-loop/
  mcp.md, the conventions tool-group table) and the doc comments that
  named it (hive-sock-client's response timeout, ensure_repo_creation_
  disabled, the security doc's merge-gate bullet)

ToolGroup::Forge is kept with no tools, the same way b88a5b24 kept
Lifecycle, so existing meta/capabilities.json grants still parse.

Forge state is untouched: existing agents/* repos keep their collaborators
and operators-team branch protection. The swarm-controller's own
create_repo (config-org repos) is a different path and is unchanged.

Closes #4849
This commit is contained in:
atlas 2026-09-30 23:42:15 +02:00 • committed by mara
commit 7d217f8267
14 changed files with 43 additions and 230 deletions

View file

@ -165,9 +165,9 @@ pub enum ToolGroup {
/// `request_schedule_prompt`, `fire_schedule_now`, `cancel_schedule`,
/// `edit_schedule`, `list_schedules` - *(privileged)*
Scheduling,
/// `create_repo` — create git repos through hive-c0re (the only path
/// now that agents can't create them directly). Opt-in per
/// agent so the operator controls who can spin up repos.
/// Gates no tool today — `create_repo`, its only member, was removed
/// with no replacement. Kept so existing `meta/capabilities.json`
/// grants still parse; `tools()` returns `&[]`.
Forge,
/// Gates whether the `bash` MCP server (`mcp__bash__run`/`status`/
/// `kill`) is rendered into the agent's config at all — see
@ -222,8 +222,8 @@ impl ToolGroup {
/// The MCP tool names (without the `mcp__hyperhive__` prefix) in this group.
/// Returns `&[]` for `WebTools` (it enables Claude built-in tools, not MCP
/// tools — see `builtin_tools()`) and for `Lifecycle` / `Approvals`
/// (their tools were removed); see each variant's doc comment.
/// tools — see `builtin_tools()`) and for `Lifecycle` / `Approvals` /
/// `Forge` (their tools were removed); see each variant's doc comment.
#[must_use]
pub fn tools(self) -> &'static [&'static str] {
match self {
@ -237,8 +237,7 @@ impl ToolGroup {
"edit_schedule",
"list_schedules",
],
Self::Forge => &["create_repo"],
// All four empty, for four different reasons — see each
// All five empty, for different reasons — see each
// variant's own doc comment above. `Execution` grants the
// out-of-process `bash` MCP server
// (`mcp__bash__run`/`status`/`kill`), gated at config-render
@ -247,13 +246,15 @@ impl ToolGroup {
// out-of-process server has no later enforcement point, so
// that gate is the actual security boundary. `WebTools`
// grants Claude built-in tools, not MCP ones; see
// `builtin_tools()`. `Lifecycle` and `Approvals` each listed
// exactly one tool — `list_containers` and
// `request_update_meta_inputs` respectively — and both tools
// were removed outright; the variants stay so existing
// grants parse, and `Approvals` still gates
// `builtin_tools()`. `Lifecycle`, `Approvals` and `Forge` each
// listed exactly one tool — `list_containers`,
// `request_update_meta_inputs` and `create_repo` respectively
// — and all three tools were removed outright; the variants
// stay so existing grants parse, and `Approvals` still gates
// `cancel_loose_end`'s approval-cancel arm server-side.
Self::Lifecycle | Self::Approvals | Self::Execution | Self::WebTools => &[],
Self::Lifecycle | Self::Approvals | Self::Forge | Self::Execution | Self::WebTools => {
&[]
}
}
}
@ -342,9 +343,7 @@ impl ToolGroup {
Self::Scheduling => {
"request_schedule_prompt and related — operator-visible scheduled prompts (privileged)"
}
Self::Forge => {
"create_repo — create git repos through hive-c0re (operator-gated merge)"
}
Self::Forge => "no tools — vestigial since create_repo was removed",
Self::Execution => {
"run, status — run shell commands via mcp__bash__run / mcp__bash__status"
}