[finding] MCPServerPlugin's own docblock still teaches the deprecated stdio trigger — plugin.ts:112-122 disagrees with plugin.ts:234-239 twelve lines below it #14473

Description

@os-litant

Out-of-scope by-product of the skills optimization flight on #14305. It is the source of a defect that already shipped once: the flight's MCP section was written from this docblock and inherited its error, caught in contract review round 1 and fixed in PR #14463 at 5dabfd2a. Filed unassigned. A code comment disagreeing with its own code — no spec .describe() twin is owed.

The drift

packages/mcp/src/plugin.ts:112-122, the class docblock:

 * 2. **start** — … Starts the long-lived transport (stdio) only when
* `autoStart` is enabled or `OS_MCP_SERVER_ENABLED` is explicitly `true` — …
*
* Environment Variables:
* - `OS_MCP_SERVER_ENABLED` — HTTP surface default-on; `false` disables it,
* explicit `true` additionally auto-starts the stdio transport

packages/mcp/src/plugin.ts:226-239, the code it documents:

// ── stdio auto-start decision (opt-in, its OWN switch) ──// … it stays opt-in via a SEPARATE switch// (`OS_MCP_STDIO_ENABLED` / the `autoStart` option), never the HTTP var.conststdio=resolveMcpStdioAutoStart();constshouldStart=this.options.autoStart||stdio.enabled;if(stdio.viaDeprecatedAlias&&!this.options.autoStart){ctx.logger.warn(
'[MCP] Starting the stdio transport via OS_MCP_SERVER_ENABLED=true is DEPRECATED — …
UseOS_MCP_STDIO_ENABLED=true(ortheplugin`autoStart`option)',);}

resolveMcpStdioAutoStart() (packages/types/src/env.ts:333-345) reads
OS_MCP_STDIO_ENABLED first and returns it clean; OS_MCP_SERVER_ENABLED=true falls through
to the legacy branch and returns viaDeprecatedAlias: true. So the docblock names only the
deprecated trigger, never the canonical one, and presents the deprecated behaviour as the
design. The env.ts docblock (:307-328) has the split right — this one was not updated with
it.

Why it is worth a card rather than a drive-by

The blast radius is measured, not hypothetical. This docblock is what a reader (human or AI)
lands on from MCPServerPlugin, and it is demonstrably what the published
skills/objectstack-ai package was written from: an author following it sets
OS_MCP_SERVER_ENABLED=true, gets a working transport plus a deprecation warning at every
boot
, and has no way from this file to learn the right spelling. One catch happened to be in
review; the next may not be.

Suggested fix

Four lines of comment in packages/mcp/src/plugin.ts:

  • Step 2: "…only when autoStart is enabled or OS_MCP_STDIO_ENABLED is truthy".
  • Environment Variables: keep OS_MCP_SERVER_ENABLED as the HTTP-surface gate only; add
    OS_MCP_STDIO_ENABLED as the stdio switch; mark the legacy OS_MCP_SERVER_ENABLED=true
    stdio trigger deprecated, matching the warning string 100 lines below.

Worth checking whether the same pre-split wording survives in packages/mcp/README.md or the
docs tree; this audit only measured the plugin docblock. Related, closed, not a duplicate:
#9579 (packages/mcp/README.md documenting runtime methods that do not exist) is the same
defect class on a neighbouring file, and its close-out did not cover this span.

Dedupe: one targeted search_issues over this repo (repo-scoped REST answers 403 for this
seat), returning a non-empty result set, so the session's search is not in the silent-zero
mode. Nothing open covers this.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions

      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
       blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
      }
      } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
      })();
      (function(){
      try {
      var __m = "github.com";
      var __re = new RegExp('^' + "github\\.com" + '
      
      Skip to content

      [finding] MCPServerPlugin's own docblock still teaches the deprecated stdio trigger — plugin.ts:112-122 disagrees with plugin.ts:234-239 twelve lines below it #14473

      Description

      @os-litant

      Out-of-scope by-product of the skills optimization flight on #14305. It is the source of a defect that already shipped once: the flight's MCP section was written from this docblock and inherited its error, caught in contract review round 1 and fixed in PR #14463 at 5dabfd2a. Filed unassigned. A code comment disagreeing with its own code — no spec .describe() twin is owed.

      The drift

      packages/mcp/src/plugin.ts:112-122, the class docblock:

       * 2. **start** — … Starts the long-lived transport (stdio) only when
      * `autoStart` is enabled or `OS_MCP_SERVER_ENABLED` is explicitly `true` — …
      *
      * Environment Variables:
      * - `OS_MCP_SERVER_ENABLED` — HTTP surface default-on; `false` disables it,
      * explicit `true` additionally auto-starts the stdio transport
      

      packages/mcp/src/plugin.ts:226-239, the code it documents:

      // ── stdio auto-start decision (opt-in, its OWN switch) ──// … it stays opt-in via a SEPARATE switch// (`OS_MCP_STDIO_ENABLED` / the `autoStart` option), never the HTTP var.conststdio=resolveMcpStdioAutoStart();constshouldStart=this.options.autoStart||stdio.enabled;if(stdio.viaDeprecatedAlias&&!this.options.autoStart){ctx.logger.warn(
      '[MCP] Starting the stdio transport via OS_MCP_SERVER_ENABLED=true is DEPRECATED — …
      UseOS_MCP_STDIO_ENABLED=true(ortheplugin`autoStart`option)',);}

      resolveMcpStdioAutoStart() (packages/types/src/env.ts:333-345) reads
      OS_MCP_STDIO_ENABLED first and returns it clean; OS_MCP_SERVER_ENABLED=true falls through
      to the legacy branch and returns viaDeprecatedAlias: true. So the docblock names only the
      deprecated trigger, never the canonical one, and presents the deprecated behaviour as the
      design. The env.ts docblock (:307-328) has the split right — this one was not updated with
      it.

      Why it is worth a card rather than a drive-by

      The blast radius is measured, not hypothetical. This docblock is what a reader (human or AI)
      lands on from MCPServerPlugin, and it is demonstrably what the published
      skills/objectstack-ai package was written from: an author following it sets
      OS_MCP_SERVER_ENABLED=true, gets a working transport plus a deprecation warning at every
      boot
      , and has no way from this file to learn the right spelling. One catch happened to be in
      review; the next may not be.

      Suggested fix

      Four lines of comment in packages/mcp/src/plugin.ts:

      • Step 2: "…only when autoStart is enabled or OS_MCP_STDIO_ENABLED is truthy".
      • Environment Variables: keep OS_MCP_SERVER_ENABLED as the HTTP-surface gate only; add
        OS_MCP_STDIO_ENABLED as the stdio switch; mark the legacy OS_MCP_SERVER_ENABLED=true
        stdio trigger deprecated, matching the warning string 100 lines below.

      Worth checking whether the same pre-split wording survives in packages/mcp/README.md or the
      docs tree; this audit only measured the plugin docblock. Related, closed, not a duplicate:
      #9579 (packages/mcp/README.md documenting runtime methods that do not exist) is the same
      defect class on a neighbouring file, and its close-out did not cover this span.

      Dedupe: one targeted search_issues over this repo (repo-scoped REST answers 403 for this
      seat), returning a non-empty result set, so the session's search is not in the silent-zero
      mode. Nothing open covers this.

      Activity

      Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

      Metadata

      Metadata

      Assignees

      No one assigned

        Type

        No type

        Projects

        No projects

          Milestone

          No milestone

          Relationships

          None yet

          Development

          No branches or pull requests

          Issue actions

          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
          Skip to content

          [finding] MCPServerPlugin's own docblock still teaches the deprecated stdio trigger — plugin.ts:112-122 disagrees with plugin.ts:234-239 twelve lines below it #14473

          Description

          @os-litant

          Out-of-scope by-product of the skills optimization flight on #14305. It is the source of a defect that already shipped once: the flight's MCP section was written from this docblock and inherited its error, caught in contract review round 1 and fixed in PR #14463 at 5dabfd2a. Filed unassigned. A code comment disagreeing with its own code — no spec .describe() twin is owed.

          The drift

          packages/mcp/src/plugin.ts:112-122, the class docblock:

           * 2. **start** — … Starts the long-lived transport (stdio) only when
          * `autoStart` is enabled or `OS_MCP_SERVER_ENABLED` is explicitly `true` — …
          *
          * Environment Variables:
          * - `OS_MCP_SERVER_ENABLED` — HTTP surface default-on; `false` disables it,
          * explicit `true` additionally auto-starts the stdio transport
          

          packages/mcp/src/plugin.ts:226-239, the code it documents:

          // ── stdio auto-start decision (opt-in, its OWN switch) ──// … it stays opt-in via a SEPARATE switch// (`OS_MCP_STDIO_ENABLED` / the `autoStart` option), never the HTTP var.conststdio=resolveMcpStdioAutoStart();constshouldStart=this.options.autoStart||stdio.enabled;if(stdio.viaDeprecatedAlias&&!this.options.autoStart){ctx.logger.warn(
          '[MCP] Starting the stdio transport via OS_MCP_SERVER_ENABLED=true is DEPRECATED — …
          UseOS_MCP_STDIO_ENABLED=true(ortheplugin`autoStart`option)',);}

          resolveMcpStdioAutoStart() (packages/types/src/env.ts:333-345) reads
          OS_MCP_STDIO_ENABLED first and returns it clean; OS_MCP_SERVER_ENABLED=true falls through
          to the legacy branch and returns viaDeprecatedAlias: true. So the docblock names only the
          deprecated trigger, never the canonical one, and presents the deprecated behaviour as the
          design. The env.ts docblock (:307-328) has the split right — this one was not updated with
          it.

          Why it is worth a card rather than a drive-by

          The blast radius is measured, not hypothetical. This docblock is what a reader (human or AI)
          lands on from MCPServerPlugin, and it is demonstrably what the published
          skills/objectstack-ai package was written from: an author following it sets
          OS_MCP_SERVER_ENABLED=true, gets a working transport plus a deprecation warning at every
          boot
          , and has no way from this file to learn the right spelling. One catch happened to be in
          review; the next may not be.

          Suggested fix

          Four lines of comment in packages/mcp/src/plugin.ts:

          • Step 2: "…only when autoStart is enabled or OS_MCP_STDIO_ENABLED is truthy".
          • Environment Variables: keep OS_MCP_SERVER_ENABLED as the HTTP-surface gate only; add
            OS_MCP_STDIO_ENABLED as the stdio switch; mark the legacy OS_MCP_SERVER_ENABLED=true
            stdio trigger deprecated, matching the warning string 100 lines below.

          Worth checking whether the same pre-split wording survives in packages/mcp/README.md or the
          docs tree; this audit only measured the plugin docblock. Related, closed, not a duplicate:
          #9579 (packages/mcp/README.md documenting runtime methods that do not exist) is the same
          defect class on a neighbouring file, and its close-out did not cover this span.

          Dedupe: one targeted search_issues over this repo (repo-scoped REST answers 403 for this
          seat), returning a non-empty result set, so the session's search is not in the silent-zero
          mode. Nothing open covers this.

          Activity

          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

          Metadata

          Metadata

          Assignees

          No one assigned

            Type

            No type

            Projects

            No projects

              Milestone

              No milestone

              Relationships

              None yet

              Development

              No branches or pull requests

              Issue actions

              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
              Skip to content

              [finding] MCPServerPlugin's own docblock still teaches the deprecated stdio trigger — plugin.ts:112-122 disagrees with plugin.ts:234-239 twelve lines below it #14473

              Description

              @os-litant

              Out-of-scope by-product of the skills optimization flight on #14305. It is the source of a defect that already shipped once: the flight's MCP section was written from this docblock and inherited its error, caught in contract review round 1 and fixed in PR #14463 at 5dabfd2a. Filed unassigned. A code comment disagreeing with its own code — no spec .describe() twin is owed.

              The drift

              packages/mcp/src/plugin.ts:112-122, the class docblock:

               * 2. **start** — … Starts the long-lived transport (stdio) only when
              * `autoStart` is enabled or `OS_MCP_SERVER_ENABLED` is explicitly `true` — …
              *
              * Environment Variables:
              * - `OS_MCP_SERVER_ENABLED` — HTTP surface default-on; `false` disables it,
              * explicit `true` additionally auto-starts the stdio transport
              

              packages/mcp/src/plugin.ts:226-239, the code it documents:

              // ── stdio auto-start decision (opt-in, its OWN switch) ──// … it stays opt-in via a SEPARATE switch// (`OS_MCP_STDIO_ENABLED` / the `autoStart` option), never the HTTP var.conststdio=resolveMcpStdioAutoStart();constshouldStart=this.options.autoStart||stdio.enabled;if(stdio.viaDeprecatedAlias&&!this.options.autoStart){ctx.logger.warn(
              '[MCP] Starting the stdio transport via OS_MCP_SERVER_ENABLED=true is DEPRECATED — …
              UseOS_MCP_STDIO_ENABLED=true(ortheplugin`autoStart`option)',);}

              resolveMcpStdioAutoStart() (packages/types/src/env.ts:333-345) reads
              OS_MCP_STDIO_ENABLED first and returns it clean; OS_MCP_SERVER_ENABLED=true falls through
              to the legacy branch and returns viaDeprecatedAlias: true. So the docblock names only the
              deprecated trigger, never the canonical one, and presents the deprecated behaviour as the
              design. The env.ts docblock (:307-328) has the split right — this one was not updated with
              it.

              Why it is worth a card rather than a drive-by

              The blast radius is measured, not hypothetical. This docblock is what a reader (human or AI)
              lands on from MCPServerPlugin, and it is demonstrably what the published
              skills/objectstack-ai package was written from: an author following it sets
              OS_MCP_SERVER_ENABLED=true, gets a working transport plus a deprecation warning at every
              boot
              , and has no way from this file to learn the right spelling. One catch happened to be in
              review; the next may not be.

              Suggested fix

              Four lines of comment in packages/mcp/src/plugin.ts:

              • Step 2: "…only when autoStart is enabled or OS_MCP_STDIO_ENABLED is truthy".
              • Environment Variables: keep OS_MCP_SERVER_ENABLED as the HTTP-surface gate only; add
                OS_MCP_STDIO_ENABLED as the stdio switch; mark the legacy OS_MCP_SERVER_ENABLED=true
                stdio trigger deprecated, matching the warning string 100 lines below.

              Worth checking whether the same pre-split wording survives in packages/mcp/README.md or the
              docs tree; this audit only measured the plugin docblock. Related, closed, not a duplicate:
              #9579 (packages/mcp/README.md documenting runtime methods that do not exist) is the same
              defect class on a neighbouring file, and its close-out did not cover this span.

              Dedupe: one targeted search_issues over this repo (repo-scoped REST answers 403 for this
              seat), returning a non-empty result set, so the session's search is not in the silent-zero
              mode. Nothing open covers this.

              Activity

              Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

              Metadata

              Metadata

              Assignees

              No one assigned

                Type

                No type

                Projects

                No projects

                  Milestone

                  No milestone

                  Relationships

                  None yet

                  Development

                  No branches or pull requests

                  Issue actions

                  , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
                  Skip to content

                  [finding] MCPServerPlugin's own docblock still teaches the deprecated stdio trigger — plugin.ts:112-122 disagrees with plugin.ts:234-239 twelve lines below it #14473

                  Description

                  @os-litant

                  Out-of-scope by-product of the skills optimization flight on #14305. It is the source of a defect that already shipped once: the flight's MCP section was written from this docblock and inherited its error, caught in contract review round 1 and fixed in PR #14463 at 5dabfd2a. Filed unassigned. A code comment disagreeing with its own code — no spec .describe() twin is owed.

                  The drift

                  packages/mcp/src/plugin.ts:112-122, the class docblock:

                   * 2. **start** — … Starts the long-lived transport (stdio) only when
                  * `autoStart` is enabled or `OS_MCP_SERVER_ENABLED` is explicitly `true` — …
                  *
                  * Environment Variables:
                  * - `OS_MCP_SERVER_ENABLED` — HTTP surface default-on; `false` disables it,
                  * explicit `true` additionally auto-starts the stdio transport
                  

                  packages/mcp/src/plugin.ts:226-239, the code it documents:

                  // ── stdio auto-start decision (opt-in, its OWN switch) ──// … it stays opt-in via a SEPARATE switch// (`OS_MCP_STDIO_ENABLED` / the `autoStart` option), never the HTTP var.conststdio=resolveMcpStdioAutoStart();constshouldStart=this.options.autoStart||stdio.enabled;if(stdio.viaDeprecatedAlias&&!this.options.autoStart){ctx.logger.warn(
                  '[MCP] Starting the stdio transport via OS_MCP_SERVER_ENABLED=true is DEPRECATED — …
                  UseOS_MCP_STDIO_ENABLED=true(ortheplugin`autoStart`option)',);}

                  resolveMcpStdioAutoStart() (packages/types/src/env.ts:333-345) reads
                  OS_MCP_STDIO_ENABLED first and returns it clean; OS_MCP_SERVER_ENABLED=true falls through
                  to the legacy branch and returns viaDeprecatedAlias: true. So the docblock names only the
                  deprecated trigger, never the canonical one, and presents the deprecated behaviour as the
                  design. The env.ts docblock (:307-328) has the split right — this one was not updated with
                  it.

                  Why it is worth a card rather than a drive-by

                  The blast radius is measured, not hypothetical. This docblock is what a reader (human or AI)
                  lands on from MCPServerPlugin, and it is demonstrably what the published
                  skills/objectstack-ai package was written from: an author following it sets
                  OS_MCP_SERVER_ENABLED=true, gets a working transport plus a deprecation warning at every
                  boot
                  , and has no way from this file to learn the right spelling. One catch happened to be in
                  review; the next may not be.

                  Suggested fix

                  Four lines of comment in packages/mcp/src/plugin.ts:

                  • Step 2: "…only when autoStart is enabled or OS_MCP_STDIO_ENABLED is truthy".
                  • Environment Variables: keep OS_MCP_SERVER_ENABLED as the HTTP-surface gate only; add
                    OS_MCP_STDIO_ENABLED as the stdio switch; mark the legacy OS_MCP_SERVER_ENABLED=true
                    stdio trigger deprecated, matching the warning string 100 lines below.

                  Worth checking whether the same pre-split wording survives in packages/mcp/README.md or the
                  docs tree; this audit only measured the plugin docblock. Related, closed, not a duplicate:
                  #9579 (packages/mcp/README.md documenting runtime methods that do not exist) is the same
                  defect class on a neighbouring file, and its close-out did not cover this span.

                  Dedupe: one targeted search_issues over this repo (repo-scoped REST answers 403 for this
                  seat), returning a non-empty result set, so the session's search is not in the silent-zero
                  mode. Nothing open covers this.

                  Activity

                  Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                  Metadata

                  Metadata

                  Assignees

                  No one assigned

                    Type

                    No type

                    Projects

                    No projects

                      Milestone

                      No milestone

                      Relationships

                      None yet

                      Development

                      No branches or pull requests

                      Issue actions

                      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                      Skip to content

                      [finding] MCPServerPlugin's own docblock still teaches the deprecated stdio trigger — plugin.ts:112-122 disagrees with plugin.ts:234-239 twelve lines below it #14473

                      Description

                      @os-litant

                      Out-of-scope by-product of the skills optimization flight on #14305. It is the source of a defect that already shipped once: the flight's MCP section was written from this docblock and inherited its error, caught in contract review round 1 and fixed in PR #14463 at 5dabfd2a. Filed unassigned. A code comment disagreeing with its own code — no spec .describe() twin is owed.

                      The drift

                      packages/mcp/src/plugin.ts:112-122, the class docblock:

                       * 2. **start** — … Starts the long-lived transport (stdio) only when
                      * `autoStart` is enabled or `OS_MCP_SERVER_ENABLED` is explicitly `true` — …
                      *
                      * Environment Variables:
                      * - `OS_MCP_SERVER_ENABLED` — HTTP surface default-on; `false` disables it,
                      * explicit `true` additionally auto-starts the stdio transport
                      

                      packages/mcp/src/plugin.ts:226-239, the code it documents:

                      // ── stdio auto-start decision (opt-in, its OWN switch) ──// … it stays opt-in via a SEPARATE switch// (`OS_MCP_STDIO_ENABLED` / the `autoStart` option), never the HTTP var.conststdio=resolveMcpStdioAutoStart();constshouldStart=this.options.autoStart||stdio.enabled;if(stdio.viaDeprecatedAlias&&!this.options.autoStart){ctx.logger.warn(
                      '[MCP] Starting the stdio transport via OS_MCP_SERVER_ENABLED=true is DEPRECATED — …
                      UseOS_MCP_STDIO_ENABLED=true(ortheplugin`autoStart`option)',);}

                      resolveMcpStdioAutoStart() (packages/types/src/env.ts:333-345) reads
                      OS_MCP_STDIO_ENABLED first and returns it clean; OS_MCP_SERVER_ENABLED=true falls through
                      to the legacy branch and returns viaDeprecatedAlias: true. So the docblock names only the
                      deprecated trigger, never the canonical one, and presents the deprecated behaviour as the
                      design. The env.ts docblock (:307-328) has the split right — this one was not updated with
                      it.

                      Why it is worth a card rather than a drive-by

                      The blast radius is measured, not hypothetical. This docblock is what a reader (human or AI)
                      lands on from MCPServerPlugin, and it is demonstrably what the published
                      skills/objectstack-ai package was written from: an author following it sets
                      OS_MCP_SERVER_ENABLED=true, gets a working transport plus a deprecation warning at every
                      boot
                      , and has no way from this file to learn the right spelling. One catch happened to be in
                      review; the next may not be.

                      Suggested fix

                      Four lines of comment in packages/mcp/src/plugin.ts:

                      • Step 2: "…only when autoStart is enabled or OS_MCP_STDIO_ENABLED is truthy".
                      • Environment Variables: keep OS_MCP_SERVER_ENABLED as the HTTP-surface gate only; add
                        OS_MCP_STDIO_ENABLED as the stdio switch; mark the legacy OS_MCP_SERVER_ENABLED=true
                        stdio trigger deprecated, matching the warning string 100 lines below.

                      Worth checking whether the same pre-split wording survives in packages/mcp/README.md or the
                      docs tree; this audit only measured the plugin docblock. Related, closed, not a duplicate:
                      #9579 (packages/mcp/README.md documenting runtime methods that do not exist) is the same
                      defect class on a neighbouring file, and its close-out did not cover this span.

                      Dedupe: one targeted search_issues over this repo (repo-scoped REST answers 403 for this
                      seat), returning a non-empty result set, so the session's search is not in the silent-zero
                      mode. Nothing open covers this.

                      Activity

                      Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                      Metadata

                      Metadata

                      Assignees

                      No one assigned

                        Type

                        No type

                        Projects

                        No projects

                          Milestone

                          No milestone

                          Relationships

                          None yet

                          Development

                          No branches or pull requests

                          Issue actions

                          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                          Skip to content

                          [finding] MCPServerPlugin's own docblock still teaches the deprecated stdio trigger — plugin.ts:112-122 disagrees with plugin.ts:234-239 twelve lines below it #14473

                          Description

                          @os-litant

                          Out-of-scope by-product of the skills optimization flight on #14305. It is the source of a defect that already shipped once: the flight's MCP section was written from this docblock and inherited its error, caught in contract review round 1 and fixed in PR #14463 at 5dabfd2a. Filed unassigned. A code comment disagreeing with its own code — no spec .describe() twin is owed.

                          The drift

                          packages/mcp/src/plugin.ts:112-122, the class docblock:

                           * 2. **start** — … Starts the long-lived transport (stdio) only when
                          * `autoStart` is enabled or `OS_MCP_SERVER_ENABLED` is explicitly `true` — …
                          *
                          * Environment Variables:
                          * - `OS_MCP_SERVER_ENABLED` — HTTP surface default-on; `false` disables it,
                          * explicit `true` additionally auto-starts the stdio transport
                          

                          packages/mcp/src/plugin.ts:226-239, the code it documents:

                          // ── stdio auto-start decision (opt-in, its OWN switch) ──// … it stays opt-in via a SEPARATE switch// (`OS_MCP_STDIO_ENABLED` / the `autoStart` option), never the HTTP var.conststdio=resolveMcpStdioAutoStart();constshouldStart=this.options.autoStart||stdio.enabled;if(stdio.viaDeprecatedAlias&&!this.options.autoStart){ctx.logger.warn(
                          '[MCP] Starting the stdio transport via OS_MCP_SERVER_ENABLED=true is DEPRECATED — …
                          UseOS_MCP_STDIO_ENABLED=true(ortheplugin`autoStart`option)',);}

                          resolveMcpStdioAutoStart() (packages/types/src/env.ts:333-345) reads
                          OS_MCP_STDIO_ENABLED first and returns it clean; OS_MCP_SERVER_ENABLED=true falls through
                          to the legacy branch and returns viaDeprecatedAlias: true. So the docblock names only the
                          deprecated trigger, never the canonical one, and presents the deprecated behaviour as the
                          design. The env.ts docblock (:307-328) has the split right — this one was not updated with
                          it.

                          Why it is worth a card rather than a drive-by

                          The blast radius is measured, not hypothetical. This docblock is what a reader (human or AI)
                          lands on from MCPServerPlugin, and it is demonstrably what the published
                          skills/objectstack-ai package was written from: an author following it sets
                          OS_MCP_SERVER_ENABLED=true, gets a working transport plus a deprecation warning at every
                          boot
                          , and has no way from this file to learn the right spelling. One catch happened to be in
                          review; the next may not be.

                          Suggested fix

                          Four lines of comment in packages/mcp/src/plugin.ts:

                          • Step 2: "…only when autoStart is enabled or OS_MCP_STDIO_ENABLED is truthy".
                          • Environment Variables: keep OS_MCP_SERVER_ENABLED as the HTTP-surface gate only; add
                            OS_MCP_STDIO_ENABLED as the stdio switch; mark the legacy OS_MCP_SERVER_ENABLED=true
                            stdio trigger deprecated, matching the warning string 100 lines below.

                          Worth checking whether the same pre-split wording survives in packages/mcp/README.md or the
                          docs tree; this audit only measured the plugin docblock. Related, closed, not a duplicate:
                          #9579 (packages/mcp/README.md documenting runtime methods that do not exist) is the same
                          defect class on a neighbouring file, and its close-out did not cover this span.

                          Dedupe: one targeted search_issues over this repo (repo-scoped REST answers 403 for this
                          seat), returning a non-empty result set, so the session's search is not in the silent-zero
                          mode. Nothing open covers this.

                          Activity

                          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                          Metadata

                          Metadata

                          Assignees

                          No one assigned

                            Type

                            No type

                            Projects

                            No projects

                              Milestone

                              No milestone

                              Relationships

                              None yet

                              Development

                              No branches or pull requests

                              Issue actions

                              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
                              Skip to content

                              [finding] MCPServerPlugin's own docblock still teaches the deprecated stdio trigger — plugin.ts:112-122 disagrees with plugin.ts:234-239 twelve lines below it #14473

                              Description

                              @os-litant

                              Out-of-scope by-product of the skills optimization flight on #14305. It is the source of a defect that already shipped once: the flight's MCP section was written from this docblock and inherited its error, caught in contract review round 1 and fixed in PR #14463 at 5dabfd2a. Filed unassigned. A code comment disagreeing with its own code — no spec .describe() twin is owed.

                              The drift

                              packages/mcp/src/plugin.ts:112-122, the class docblock:

                               * 2. **start** — … Starts the long-lived transport (stdio) only when
                              * `autoStart` is enabled or `OS_MCP_SERVER_ENABLED` is explicitly `true` — …
                              *
                              * Environment Variables:
                              * - `OS_MCP_SERVER_ENABLED` — HTTP surface default-on; `false` disables it,
                              * explicit `true` additionally auto-starts the stdio transport
                              

                              packages/mcp/src/plugin.ts:226-239, the code it documents:

                              // ── stdio auto-start decision (opt-in, its OWN switch) ──// … it stays opt-in via a SEPARATE switch// (`OS_MCP_STDIO_ENABLED` / the `autoStart` option), never the HTTP var.conststdio=resolveMcpStdioAutoStart();constshouldStart=this.options.autoStart||stdio.enabled;if(stdio.viaDeprecatedAlias&&!this.options.autoStart){ctx.logger.warn(
                              '[MCP] Starting the stdio transport via OS_MCP_SERVER_ENABLED=true is DEPRECATED — …
                              UseOS_MCP_STDIO_ENABLED=true(ortheplugin`autoStart`option)',);}

                              resolveMcpStdioAutoStart() (packages/types/src/env.ts:333-345) reads
                              OS_MCP_STDIO_ENABLED first and returns it clean; OS_MCP_SERVER_ENABLED=true falls through
                              to the legacy branch and returns viaDeprecatedAlias: true. So the docblock names only the
                              deprecated trigger, never the canonical one, and presents the deprecated behaviour as the
                              design. The env.ts docblock (:307-328) has the split right — this one was not updated with
                              it.

                              Why it is worth a card rather than a drive-by

                              The blast radius is measured, not hypothetical. This docblock is what a reader (human or AI)
                              lands on from MCPServerPlugin, and it is demonstrably what the published
                              skills/objectstack-ai package was written from: an author following it sets
                              OS_MCP_SERVER_ENABLED=true, gets a working transport plus a deprecation warning at every
                              boot
                              , and has no way from this file to learn the right spelling. One catch happened to be in
                              review; the next may not be.

                              Suggested fix

                              Four lines of comment in packages/mcp/src/plugin.ts:

                              • Step 2: "…only when autoStart is enabled or OS_MCP_STDIO_ENABLED is truthy".
                              • Environment Variables: keep OS_MCP_SERVER_ENABLED as the HTTP-surface gate only; add
                                OS_MCP_STDIO_ENABLED as the stdio switch; mark the legacy OS_MCP_SERVER_ENABLED=true
                                stdio trigger deprecated, matching the warning string 100 lines below.

                              Worth checking whether the same pre-split wording survives in packages/mcp/README.md or the
                              docs tree; this audit only measured the plugin docblock. Related, closed, not a duplicate:
                              #9579 (packages/mcp/README.md documenting runtime methods that do not exist) is the same
                              defect class on a neighbouring file, and its close-out did not cover this span.

                              Dedupe: one targeted search_issues over this repo (repo-scoped REST answers 403 for this
                              seat), returning a non-empty result set, so the session's search is not in the silent-zero
                              mode. Nothing open covers this.

                              Activity

                              Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                              Metadata

                              Metadata

                              Assignees

                              No one assigned

                                Type

                                No type

                                Projects

                                No projects

                                  Milestone

                                  No milestone

                                  Relationships

                                  None yet

                                  Development

                                  No branches or pull requests

                                  Issue actions