{"record":{"id":"9293dc2f32c349a8","repo":"Hmbown/CodeWhale","slug":"refusing-to-operation-mcp-server-server-name-from-plugin","errorCode":null,"errorMessage":"Refusing to {operation} MCP server '{server_name}' from plugin bundle `{plugin_name}`: {reason}. {remediation}","messagePattern":"Refusing to (.+?) MCP server '(.+?)' from plugin bundle `(.+?)`: (.+?)\\. (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"crates/tui/src/mcp.rs","lineNumber":764,"sourceCode":"    fn required_capability(&self) -> crate::plugins::activation::PluginActivationCapability {\n        if self.approved_remote_endpoint.is_some() {\n            crate::plugins::activation::PluginActivationCapability::McpRemote\n        } else {\n            crate::plugins::activation::PluginActivationCapability::McpStdio\n        }\n    }\n\n    fn validate_before_use(&self, server_name: &str, operation: &str) -> Result<()> {\n        let remediation = format!(\n            \"Run `/plugin reload`, inspect `/plugin show {0}`, then repeat the displayed trust command and `/plugin enable {0}` before retrying\",\n            self.authority.plugin_name\n        );\n        crate::plugins::registry::verify_plugin_component_authority(\n            &self.authority,\n            self.required_capability(),\n        )\n        .map_err(|reason| {\n            anyhow::anyhow!(\n                \"Refusing to {operation} MCP server '{server_name}' from plugin bundle `{}`: {reason}. {remediation}\",\n                self.authority.plugin_name\n            )\n        })\n    }\n\n    fn validate_remote_endpoint(&self, server_name: &str, endpoint: &str) -> Result<()> {\n        let (endpoint, origin) = reviewed_remote_endpoint_identity(endpoint)?;\n        if self.approved_remote_endpoint.as_deref() != Some(endpoint.as_str())\n            || self.approved_remote_origin.as_deref() != Some(origin.as_str())\n        {\n            anyhow::bail!(\n                \"Refusing MCP server '{server_name}': its remote endpoint no longer matches the reviewed plugin origin\"\n            );\n        }\n        Ok(())\n    }\n","sourceCodeStart":746,"sourceCodeEnd":782,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/433685b2024e7bc4c99e1e2e326bcad39b4d9d65/crates/tui/src/mcp.rs#L746-L782","documentation":"This error is thrown when the MCP subsystem refuses to start or otherwise operate an MCP server that comes from a plugin bundle, because the plugin's authority check (verify_plugin_component_authority) failed to confirm it holds the required capability. The library blocks the operation and appends a remediation hint so the user can grant the missing authority. It is a deliberate safety gate, not a bug.","triggerScenarios":"validate_before_use is called from validate_before_stdio_spawn when spawning (or otherwise operating) a plugin-bundled MCP server whose plugin authority lacks the capability required by the server definition.","commonSituations":"A user installs a plugin bundle whose manifest declares fewer capabilities than the MCP servers it ships; the bundle was updated to require new capabilities but the user's authority grant is stale; a hand-edited plugin manifest omits a capability.","solutions":["Read the {reason} and {remediation} in the message and grant the named plugin bundle the required capability (update the plugin's authority/capability grant in your plugin config).","Reinstall or update the plugin bundle so its manifest and installed authority record are in sync.","If the plugin should not need the capability, remove the MCP server from the bundle or report the bundle's missing capability declaration to the plugin author.","As a last resort, disable the plugin MCP server so the pool stops trying to spawn it."],"exampleFix":"// before (plugin manifest)\n\"capabilities\": []\n// after\n\"capabilities\": [\"mcp:spawn\"]","handlingStrategy":"validation","validationCode":"// before spawning a plugin MCP server\nlet auth_ok = crate::plugins::registry::verify_plugin_component_authority(&authority, required_capability());\nanyhow::ensure!(auth_ok.is_ok(), \"plugin {} lacks required MCP capability\", authority.plugin_name);","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Declare all needed capabilities in the plugin manifest at authoring time","Keep capability grants in sync when updating plugin bundles","Test plugin bundles in a clean profile before distribution"],"tags":["mcp","plugin","capability","authorization"],"backgroundTag":"permission-denied","analyzedSha":"433685b2024e7bc4c99e1e2e326bcad39b4d9d65","analyzedAt":"2026-09-15T12:24:24.634Z","contentChangedAt":"2026-09-15T12:24:24.634Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}