Skip to content

config(mcp): allow the openhuman and opencompany repositories for Teeny - #189

Merged
senamakel merged 5 commits into
mainfrom
mcp-allow-products
Sep 21, 2026
Merged

senamakel merged 5 commits into
mainfrom
mcp-allow-products

Conversation

@senamakel

@senamakel senamakel commented Sep 21, 2026 •

Copy link
Copy Markdown
Member

What changed

mcp.allowed_repos in the deployed .tinysweeper.toml gains tinyhumansai/openhuman and tinyhumansai/opencompany, alongside tinyhumansai/tinysweeper.

Why

Teeny (the Discord bot, tinyhumansai/teeny-discord-bot) answers members' product questions through this MCP endpoint — search_code over the GitBooks/docs, search_issues to spot known bugs, create_issue for tickets — and #188's fail-closed allowlist (rightly) shut it out. Both product repositories are public. Teeny keeps its own client-side allowlist of exactly these two repositories, so the org-wide bearer never reaches a private repository from either side.

The same edit has already been applied on the box (/opt/tinysweeper/.tinysweeper.toml, server restarted, verified: openhuman/opencompany answer, tinyhumansai/backend is refused); this PR makes main match it.

Verification

  • cargo test --locked --features serve config:: (config validation still accepts the file: exact owner/name, inside allowed_org, no duplicates)
  • live: search_code on both repositories returns hits; a repository off the list gets repository is not in this MCP server's allowlist

Co-authored-by: Medulla medulla@tinyhumans.ai

Summary by CodeRabbit

  • Configuration
    • Expanded the set of repositories available to the MCP integration.
    • Added guidance clarifying the repositories’ intended use and cautioning against including private repositories.

senamakel and others added 2 commits September 21, 2026 21:56
Update the pinned commit of the tinyagents submodule to incorporate the latest upstream changes.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
The MCP configuration now includes the openhuman and opencompany repositories alongside tinysweeper, enabling the Discord bot to access documentation and file bug reports for all three public product repositories. The comment clarifies that private repositories must remain off this list because the bearer token is shared with a server-wide service.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
@tinysweeper

tinysweeper Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Tiny Sweeper review

Tiny Sweeper reviewed this change across 6 lanes and found 0 active actionable findings. The configuration change is safe to merge.

State: Ready for maintainer review
Priority: none
Reviewed head: 729f497f2d70
Updated: 1790008326 (Unix time)

Review snapshot

Change surface Files Review signal Count
Production 0 Active findings 0
Tests 0 Noted findings 0
Documentation 0 Resolved findings 0
Configuration 1 Pending checks/questions 0

Completeness: Complete
Test assessment: No supported feature-to-test mapping was available; this does not mean tests are absent or passed.

What changed

Expanded the MCP repository allowlist to include tinyhumansai/openhuman and tinyhumansai/opencompany, while retaining the existing tinyhumansai/tinysweeper entry.

Features

  • Modified — MCP repository allowlist expansion: Allows the Teeny Discord bot to answer questions and file bug reports from the two added public product repositories, matching the already-applied live config. (.tinysweeper.toml, .tinysweeper.toml#answer_model = "flash")

Tests

No supported feature-to-test mapping was produced. Test execution is not inferred.

Findings

No active actionable findings.

Before merge

None.

Agent review details

critique

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Positive: The entries are valid and scoped to the configured organisation, so the change is safe to merge.
  • Lane summary: The change expands the explicitly configured MCP repository allowlist to include the two intended public product repositories while retaining the existing repository. The entries are valid and scoped to the configured organisation, so this change looks safe to merge. _The code index is behind this pull request (indexed at `73237bb6360d`), so retrieved context may be out of date._ _Memory was unavailable (model: cortex: v1/recall: timed out after 10s), so this review ran without it._

security

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Positive: No wildcard or scope bypass; allowlist is exact and within the organisation scope.
  • Lane summary: The change expands the exact MCP repository allowlist to two additional repositories, with no wildcard or scope bypass. The configuration looks safe to merge. _The code index is behind this pull request (indexed at `73237bb6360d`), so retrieved context may be out of date._ _Memory was unavailable (model: cortex: v1/recall: timed out after 10s), so this review ran without it._

tests

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: No behavioural change: nothing outside documentation, configuration and tests.

commits

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: Nothing sensitive found in what this pull request commits.

description

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: Adds two public product repositories to the MCP allowlist, matching a live config change already applied. No defects introduced. _The code index is behind this pull request (indexed at `73237bb6360d`), so retrieved context may be out of date._ _Memory was unavailable (model: cortex: v1/recall: timed out after 10s), so this review ran without it._

e2e

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: No behavioural change: nothing outside documentation, configuration and tests.
Evidence and run details
  • Models: ladder/vectors, gpt-5.6-luna, deepseek/deepseek-v4-flash
  • Spend: $0.002526
  • Tokens: 44476 input · 1484 output · 8915 cached · 91 embedding
Head State Pass summary
c02421d5ad67 ready for maintainer review 0 active finding(s), 0 resolved finding(s) (at 1790008265)
729f497f2d70 ready for maintainer review 0 active finding(s), 0 resolved finding(s) (at 1790008326)

tinysweeper 0.1.0

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-21T16:33:57.383003Z c02421d PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

senamakel and others added 2 commits September 21, 2026 22:00
The worktree bootstrap moved the submodule pointer; this puts it back at
what main records so the PR is the config change alone.

Co-authored-by: Medulla <medulla@tinyhumans.ai>
Update the pinned commit for the tinyagents vendored dependency to incorporate upstream fixes and improvements.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
@coderabbitai

coderabbitai Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

Understand this PR’s impact

Explore downstream dependencies and potential security impact with Blast Radius.

View blast radius →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 642f6b34-2624-4f63-80f7-be29ae2fe743

📥 Commits

Reviewing files that changed from the base of the PR and between ce51852 and 729f497.

📒 Files selected for processing (1)
  • .tinysweeper.toml

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The [mcp] configuration now allows tinyhumansai/tinysweeper, tinyhumansai/openhuman, and tinyhumansai/opencompany. A comment identifies their use by Teeny and warns against adding private repositories.

Changes

Repository access configuration

Layer / File(s) Summary
Expand allowed repositories
.tinysweeper.toml
The allowed_repos list now contains three repositories in multi-line form. A comment documents their use by Teeny and excludes private repositories.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Feature

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: allowing the openhuman and opencompany repositories in the MCP configuration for Teeny.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

A rabbit checked the repo gate
Three bright paths now await
Teeny hops where helpers roam
Public paths remain the rule at home
Private burrows stay away
Configuration grows today

Comment @coderabbitai help to get the list of available commands.

Co-authored-by: Medulla <medulla@tinyhumans.ai>

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tinysweeper found nothing blocking. Approving.

             $0.0025 · 44,476 in / 1,484 out · 8,915 cached (20%) · ladder/vectors, gpt-5.6-luna, deepseek/deepseek-v4-flash · 91 embedded
critique:    $0.0007 · 12,211 in / 351 out   · 2,025 cached (17%) · gpt-5.6-luna
security:    $0.0017 · 26,995 in / 788 out   · 3,562 cached (13%) · gpt-5.6-luna
description: $0.0001 · 3,555 in  / 40 out    · 3,328 cached (94%) · deepseek/deepseek-v4-flash

@tinysweeper tinysweeper Bot added the priority: p3 Whenever. Cosmetic, a nicety, or a cleanup with no user visible effect. label Sep 21, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c02421d5ad

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread vendor/tinyagents Outdated
@@ -1 +1 @@
Subproject commit 44afb2e6884690a59eb43e268a09868a9852c410
Subproject commit 27a3f39dc6d7db676efe58d0f7b89752a8ab4746

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Align the tinyagents submodule with Cargo's revision

This changes the submodule from 44afb2e6 back to the older 27a3f39d, even though both tinyagents dependencies and their lockfile entries remain pinned to 44afb2e6. Consequently, checkouts and repository indexing expose an outdated harness source tree while builds use a different revision, and this older pin predates the later v2.1.1/v2.1.2 updates visible in this repository's history. Keep the gitlink at 44afb2e6 or update Cargo.toml and Cargo.lock in the same coherent dependency change.

AGENTS.md reference: AGENTS.md:L28-L29

Useful? React with 👍 / 👎.

@senamakel
senamakel merged commit e211267 into main Sep 21, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority: p3 Whenever. Cosmetic, a nicety, or a cleanup with no user visible effect.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant