fix: bump the oilpriceapi-mcp pin from 3.0.0 to 3.3.0 - #6
Merged
Merged
Conversation
The extension pinned oilpriceapi-mcp@3.0.0, which silently returns a DIFFERENT commodity than the caller asked for. Measured against the published 3.2.4 tarball across all 604 live catalog codes: 27 resolved correctly, 395 returned a different instrument, 182 were refused. 3.0.0 is two minors older and carries the same resolver. NATURAL_GAS_WAHA -> NATURAL_GAS_USD NATURAL_GAS_TTF_SPOT_EUR -> NATURAL_GAS_USD LNG_NW_EUROPE_EUR -> EUR_USD Waha is a Permian hub that trades at a deep basis discount to Henry Hub and has settled negative; TTF is European gas in EUR/MWh. Returned with isError:false, so Gemini had no way to detect the substitution and would state the wrong number as fact. Fixed upstream in mcp-server v3.3.0, verified against the published tarball. Pin updated in all six places: gemini-extension.json, package.json, package-lock.json, README.md (4 refs), GEMINI.md, tests/manifest.test.mjs. The tool-inventory assertion moves 25 -> 32. That count is a change-detector, not the safety property. All 32 tools were listed and reviewed: every one is a read verb (get/list/compare/search/lookup/market_overview), no write tool is exposed, and the two substantive assertions -- every tool carries readOnlyHint, and opa_create_price_alert is absent -- both still pass unchanged. A note in the test says to re-review rather than just edit the number next time. Baseline on origin/main: 11 pass, 0 fail. After: 11 pass, 0 fail. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015ao5paex73xXvuM424Libo
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The extension pins
oilpriceapi-mcp@3.0.0, which silently returns a different commodity than the caller asked for.Why this matters
Measured against the published 3.2.4 tarball across all 604 live catalog codes: 27 resolved correctly, 395 returned a different instrument, 182 were refused. 3.0.0 is two minors older and carries the same resolver.
NATURAL_GAS_WAHANATURAL_GAS_USDNATURAL_GAS_TTF_SPOT_EURNATURAL_GAS_USDLNG_NW_EUROPE_EUREUR_USDWaha is a Permian hub that trades at a deep basis discount to Henry Hub and has settled negative. TTF is European gas in EUR/MWh.
LNG_NW_EUROPE_EURreturned an FX rate for an LNG cargo.All with
isError: false— so Gemini had no way to detect the substitution and would state the wrong number as fact.Fixed upstream in
mcp-serverv3.3.0 and verified against the published tarball:Change
Pin updated in all six places:
gemini-extension.json,package.json,package-lock.json,README.md(4 refs),GEMINI.md,tests/manifest.test.mjs.The tool-count assertion, and why it moved
protocol.test.mjsasserted exactly 25 tools; 3.3.0 exposes 32. I did not just edit the number. All 32 were listed and reviewed — every one is a read verb (get,list,compare,search,lookup,market_overview), and no mutating tool appears. The two assertions that carry the actual safety property both still pass unchanged:readOnlyHintopa_create_price_alertis absentA comment now records that review and says to list and check the tools next time rather than editing the number.
Test evidence
🤖 Generated with Claude Code
https://claude.ai/code/session_015ao5paex73xXvuM424Libo