Skip to content

fix: bump the oilpriceapi-mcp pin from 3.0.0 to 3.3.0 - #6

Merged
karlwaldman merged 1 commit into
mainfrom
fix/bump-mcp-pin-3.3.0
Sep 13, 2026
Merged

karlwaldman merged 1 commit into
mainfrom
fix/bump-mcp-pin-3.3.0

Conversation

@karlwaldman

Copy link
Copy Markdown
Member

The extension pins oilpriceapi-mcp@3.0.0, which silently returns a different commodity than the caller asked for.

Why this matters

Measured against the published 3.2.4 tarball across all 604 live catalog codes: 27 resolved correctly, 395 returned a different instrument, 182 were refused. 3.0.0 is two minors older and carries the same resolver.

requested returned
NATURAL_GAS_WAHA NATURAL_GAS_USD
NATURAL_GAS_TTF_SPOT_EUR NATURAL_GAS_USD
LNG_NW_EUROPE_EUR EUR_USD

Waha is a Permian hub that trades at a deep basis discount to Henry Hub and has settled negative. TTF is European gas in EUR/MWh. LNG_NW_EUROPE_EUR returned an FX rate for an LNG cargo.

All with isError: false — so Gemini had no way to detect the substitution and would state the wrong number as fact.

Fixed upstream in mcp-server v3.3.0 and verified against the published tarball:

NATURAL_GAS_WAHA          -> NATURAL_GAS_WAHA
RBOB_GASOLINE_USD         -> RBOB_GASOLINE_USD
NATURAL_GAS_TTF_SPOT_EUR  -> NATURAL_GAS_TTF_SPOT_EUR
brent                     -> BRENT_CRUDE_USD     (natural language intact)
MCP_VERSION: 3.3.0

Change

Pin updated in all six places: gemini-extension.json, package.json, package-lock.json, README.md (4 refs), GEMINI.md, tests/manifest.test.mjs.

The tool-count assertion, and why it moved

protocol.test.mjs asserted exactly 25 tools; 3.3.0 exposes 32. I did not just edit the number. All 32 were listed and reviewed — every one is a read verb (get, list, compare, search, lookup, market_overview), and no mutating tool appears. The two assertions that carry the actual safety property both still pass unchanged:

  • every tool carries readOnlyHint
  • opa_create_price_alert is absent

A comment now records that review and says to list and check the tools next time rather than editing the number.

Test evidence

Baseline on clean origin/main:  11 pass, 0 fail
This branch:                    11 pass, 0 fail

🤖 Generated with Claude Code

https://claude.ai/code/session_015ao5paex73xXvuM424Libo

The extension pinned oilpriceapi-mcp@3.0.0, which silently returns a DIFFERENT
commodity than the caller asked for. Measured against the published 3.2.4
tarball across all 604 live catalog codes: 27 resolved correctly, 395 returned
a different instrument, 182 were refused. 3.0.0 is two minors older and carries
the same resolver.

  NATURAL_GAS_WAHA          -> NATURAL_GAS_USD
  NATURAL_GAS_TTF_SPOT_EUR  -> NATURAL_GAS_USD
  LNG_NW_EUROPE_EUR         -> EUR_USD

Waha is a Permian hub that trades at a deep basis discount to Henry Hub and has
settled negative; TTF is European gas in EUR/MWh. Returned with isError:false,
so Gemini had no way to detect the substitution and would state the wrong
number as fact. Fixed upstream in mcp-server v3.3.0, verified against the
published tarball.

Pin updated in all six places: gemini-extension.json, package.json,
package-lock.json, README.md (4 refs), GEMINI.md, tests/manifest.test.mjs.

The tool-inventory assertion moves 25 -> 32. That count is a change-detector,
not the safety property. All 32 tools were listed and reviewed: every one is a
read verb (get/list/compare/search/lookup/market_overview), no write tool is
exposed, and the two substantive assertions -- every tool carries readOnlyHint,
and opa_create_price_alert is absent -- both still pass unchanged. A note in the
test says to re-review rather than just edit the number next time.

Baseline on origin/main: 11 pass, 0 fail. After: 11 pass, 0 fail.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015ao5paex73xXvuM424Libo
@coderabbitai

coderabbitai Bot commented Sep 13, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: d2d73bf5-5cfe-4951-89fc-110cd4e8102b


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@karlwaldman
karlwaldman merged commit e3a2063 into main Sep 13, 2026
2 checks passed
@karlwaldman
karlwaldman deleted the fix/bump-mcp-pin-3.3.0 branch September 13, 2026 15:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant