From c5210a2776cdc58d52c6e1cbb08de87a670b274a Mon Sep 17 00:00:00 2001 From: Karl Waldman Date: Sun, 13 Sep 2026 11:44:16 -0400 Subject: [PATCH] fix: bump the oilpriceapi-mcp pin from 3.0.0 to 3.3.0 The extension pinned oilpriceapi-mcp@3.0.0, which silently returns a DIFFERENT commodity than the caller asked for. Measured against the published 3.2.4 tarball across all 604 live catalog codes: 27 resolved correctly, 395 returned a different instrument, 182 were refused. 3.0.0 is two minors older and carries the same resolver. NATURAL_GAS_WAHA -> NATURAL_GAS_USD NATURAL_GAS_TTF_SPOT_EUR -> NATURAL_GAS_USD LNG_NW_EUROPE_EUR -> EUR_USD Waha is a Permian hub that trades at a deep basis discount to Henry Hub and has settled negative; TTF is European gas in EUR/MWh. Returned with isError:false, so Gemini had no way to detect the substitution and would state the wrong number as fact. Fixed upstream in mcp-server v3.3.0, verified against the published tarball. Pin updated in all six places: gemini-extension.json, package.json, package-lock.json, README.md (4 refs), GEMINI.md, tests/manifest.test.mjs. The tool-inventory assertion moves 25 -> 32. That count is a change-detector, not the safety property. All 32 tools were listed and reviewed: every one is a read verb (get/list/compare/search/lookup/market_overview), no write tool is exposed, and the two substantive assertions -- every tool carries readOnlyHint, and opa_create_price_alert is absent -- both still pass unchanged. A note in the test says to re-review rather than just edit the number next time. Baseline on origin/main: 11 pass, 0 fail. After: 11 pass, 0 fail. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_015ao5paex73xXvuM424Libo --- GEMINI.md | 2 +- README.md | 8 ++++---- gemini-extension.json | 2 +- package-lock.json | 20 +++++--------------- package.json | 2 +- tests/manifest.test.mjs | 2 +- tests/protocol.test.mjs | 13 ++++++++++++- 7 files changed, 25 insertions(+), 24 deletions(-) diff --git a/GEMINI.md b/GEMINI.md index 8757a08..94ed03c 100644 --- a/GEMINI.md +++ b/GEMINI.md @@ -1,7 +1,7 @@ # OilPriceAPI Grounding Instructions This extension connects the current Gemini CLI session to the read-only -`oilpriceapi-mcp@3.0.0` tool inventory. In Gemini CLI, the tools appear with the +`oilpriceapi-mcp@3.3.0` tool inventory. In Gemini CLI, the tools appear with the `mcp_oilpriceapi_` prefix. ## Ground Product Answers diff --git a/README.md b/README.md index 16b0eb1..16d4a1b 100644 --- a/README.md +++ b/README.md @@ -46,14 +46,14 @@ Show an energy market snapshot and identify unavailable fields. What does OilPriceAPI say about refresh cadence and data rights? ``` -The extension pins `oilpriceapi-mcp@3.0.0`, starts it with `--scope read`, and +The extension pins `oilpriceapi-mcp@3.3.0`, starts it with `--scope read`, and sets a 15-second Gemini MCP request timeout. The default inventory exposes 25 read tools and no create/delete tools. Inspect the exact executable inventory: ```bash -npx -y oilpriceapi-mcp@3.0.0 --list-tools --json -npx -y oilpriceapi-mcp@3.0.0 --capabilities --json -npx -y oilpriceapi-mcp@3.0.0 doctor --demo +npx -y oilpriceapi-mcp@3.3.0 --list-tools --json +npx -y oilpriceapi-mcp@3.3.0 --capabilities --json +npx -y oilpriceapi-mcp@3.3.0 doctor --demo ``` Common tools include: diff --git a/gemini-extension.json b/gemini-extension.json index d2cab05..38b8054 100644 --- a/gemini-extension.json +++ b/gemini-extension.json @@ -16,7 +16,7 @@ "command": "npx", "args": [ "-y", - "oilpriceapi-mcp@3.0.0", + "oilpriceapi-mcp@3.3.0", "--scope", "read", "--profile", diff --git a/package-lock.json b/package-lock.json index 34a5481..6598ddf 100644 --- a/package-lock.json +++ b/package-lock.json @@ -10,7 +10,7 @@ "devDependencies": { "@google/gemini-cli": "0.49.0", "@modelcontextprotocol/sdk": "1.29.0", - "oilpriceapi-mcp": "3.0.0" + "oilpriceapi-mcp": "3.3.0" }, "engines": { "node": ">=20.0.0" @@ -1007,14 +1007,14 @@ } }, "node_modules/oilpriceapi-mcp": { - "version": "3.0.0", - "resolved": "https://registry.npmjs.org/oilpriceapi-mcp/-/oilpriceapi-mcp-3.0.0.tgz", - "integrity": "sha512-Sk/DGURhhp4nz823aaALECUOj+Q85cAvnLWtVKJ4+AbhdEunI8tfre0t0SYHiNxktImZEzfrz2P7p7QvIxbzoQ==", + "version": "3.3.0", + "resolved": "https://registry.npmjs.org/oilpriceapi-mcp/-/oilpriceapi-mcp-3.3.0.tgz", + "integrity": "sha512-hd5ptGfl6GDTG41ayLj1fdnnQXiXdLMrRgfwIijaaXb1ziYv2ljFT8IaGVCfdycKcsS8OmXsi1kYHm89V6e1QQ==", "dev": true, "license": "MIT", "dependencies": { "@modelcontextprotocol/sdk": "^1.25.2", - "zod": "^3.23.0" + "zod": "^4.4.3" }, "bin": { "oilpriceapi-mcp": "build/index.js" @@ -1023,16 +1023,6 @@ "node": ">=18.0.0" } }, - "node_modules/oilpriceapi-mcp/node_modules/zod": { - "version": "3.25.76", - "resolved": "https://registry.npmjs.org/zod/-/zod-3.25.76.tgz", - "integrity": "sha512-gzUt/qt81nXsFGKIFcC3YnfEAx5NkunCfnDlvuBSSFS02bcXu4Lmea0AFIUwbLWxWPx3d9p8S5QoaujKcNQxcQ==", - "dev": true, - "license": "MIT", - "funding": { - "url": "https://github.com/sponsors/colinhacks" - } - }, "node_modules/on-finished": { "version": "2.4.1", "resolved": "https://registry.npmjs.org/on-finished/-/on-finished-2.4.1.tgz", diff --git a/package.json b/package.json index 57538f0..2cc4edb 100644 --- a/package.json +++ b/package.json @@ -15,6 +15,6 @@ "devDependencies": { "@google/gemini-cli": "0.49.0", "@modelcontextprotocol/sdk": "1.29.0", - "oilpriceapi-mcp": "3.0.0" + "oilpriceapi-mcp": "3.3.0" } } diff --git a/tests/manifest.test.mjs b/tests/manifest.test.mjs index 1a7d601..7f39c85 100644 --- a/tests/manifest.test.mjs +++ b/tests/manifest.test.mjs @@ -23,7 +23,7 @@ test("manifest pins a bounded read-only MCP runtime", () => { assert.equal(server.command, "npx"); assert.deepEqual(server.args, [ "-y", - "oilpriceapi-mcp@3.0.0", + "oilpriceapi-mcp@3.3.0", "--scope", "read", "--profile", diff --git a/tests/protocol.test.mjs b/tests/protocol.test.mjs index aad4f90..118d39a 100644 --- a/tests/protocol.test.mjs +++ b/tests/protocol.test.mjs @@ -171,7 +171,18 @@ async function withClient(apiKey, callback) { test("Gemini manifest launches the exact read-only tool inventory", async () => { await withClient("", async (client) => { const listed = await client.listTools(); - assert.equal(listed.tools.length, 25); + // 25 -> 32 on the oilpriceapi-mcp 3.0.0 -> 3.3.0 pin bump. + // + // The count is a change-detector, not the safety property: it exists so a + // new tool cannot appear in the Gemini surface without someone looking at + // it. All 32 were reviewed on 2026-09-13 and every one is a read verb + // (get / list / compare / search / lookup / market_overview). The two + // assertions below are the actual guards and both still hold: every tool + // carries readOnlyHint, and no write tool is exposed. + // + // If this number changes again, list the tools and check them before + // editing it. + assert.equal(listed.tools.length, 32); assert.ok(listed.tools.some((tool) => tool.name === "opa_get_product_facts")); assert.ok(listed.tools.some((tool) => tool.name === "opa_get_price")); assert.ok(