Hmbown/CodeWhale · error

Refusing to MCP server ' ' from plugin bundle ` `: .

Error message

Refusing to {operation} MCP server '{server_name}' from plugin bundle `{plugin_name}`: {reason}. {remediation}

What it means

This error is thrown when the MCP subsystem refuses to start or otherwise operate an MCP server that comes from a plugin bundle, because the plugin's authority check (verify_plugin_component_authority) failed to confirm it holds the required capability. The library blocks the operation and appends a remediation hint so the user can grant the missing authority. It is a deliberate safety gate, not a bug.

Solutions

  1. Read the {reason} and {remediation} in the message and grant the named plugin bundle the required capability (update the plugin's authority/capability grant in your plugin config).
  2. Reinstall or update the plugin bundle so its manifest and installed authority record are in sync.
  3. If the plugin should not need the capability, remove the MCP server from the bundle or report the bundle's missing capability declaration to the plugin author.
  4. As a last resort, disable the plugin MCP server so the pool stops trying to spawn it.

Example fix

// before (plugin manifest)
"capabilities": []
// after
"capabilities": ["mcp:spawn"]
Defensive patterns

Strategy: validation

Validate before calling

// before spawning a plugin MCP server
let auth_ok = crate::plugins::registry::verify_plugin_component_authority(&authority, required_capability());
anyhow::ensure!(auth_ok.is_ok(), "plugin {} lacks required MCP capability", authority.plugin_name);

Prevention

When it happens

Trigger: validate_before_use is called from validate_before_stdio_spawn when spawning (or otherwise operating) a plugin-bundled MCP server whose plugin authority lacks the capability required by the server definition.

Common situations: A user installs a plugin bundle whose manifest declares fewer capabilities than the MCP servers it ships; the bundle was updated to require new capabilities but the user's authority grant is stale; a hand-edited plugin manifest omits a capability.

Understand the failure class

Background: Permission denied / not authorized / 403 Forbidden: access-control rejections when the caller lacks the required role, grant, or ownership — this error's family across 18 libraries.

Related errors


AI-assisted analysis of Hmbown/CodeWhale@433685b202 (2026-09-15). Data as JSON: /api/errors/9293dc2f32c349a8. Report an issue: GitHub.

Appendix: source

Thrown at crates/tui/src/mcp.rs:764

    fn required_capability(&self) -> crate::plugins::activation::PluginActivationCapability {
        if self.approved_remote_endpoint.is_some() {
            crate::plugins::activation::PluginActivationCapability::McpRemote
        } else {
            crate::plugins::activation::PluginActivationCapability::McpStdio
        }
    }

    fn validate_before_use(&self, server_name: &str, operation: &str) -> Result<()> {
        let remediation = format!(
            "Run `/plugin reload`, inspect `/plugin show {0}`, then repeat the displayed trust command and `/plugin enable {0}` before retrying",
            self.authority.plugin_name
        );
        crate::plugins::registry::verify_plugin_component_authority(
            &self.authority,
            self.required_capability(),
        )
        .map_err(|reason| {
            anyhow::anyhow!(
                "Refusing to {operation} MCP server '{server_name}' from plugin bundle `{}`: {reason}. {remediation}",
                self.authority.plugin_name
            )
        })
    }

    fn validate_remote_endpoint(&self, server_name: &str, endpoint: &str) -> Result<()> {
        let (endpoint, origin) = reviewed_remote_endpoint_identity(endpoint)?;
        if self.approved_remote_endpoint.as_deref() != Some(endpoint.as_str())
            || self.approved_remote_origin.as_deref() != Some(origin.as_str())
        {
            anyhow::bail!(
                "Refusing MCP server '{server_name}': its remote endpoint no longer matches the reviewed plugin origin"
            );
        }
        Ok(())
    }

View on GitHub (pinned to 433685b202)