fix(server): bound mcp tool payloads on the wire - #5481

Closed
t3dotgg wants to merge 1 commit into
mainfrom
t3code/slim-mcp-tool-payloads
Closed

fix(server): bound mcp tool payloads on the wire#5481
t3dotgg wants to merge 1 commit into
mainfrom
t3code/slim-mcp-tool-payloads

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 6, 2026

Copy link
Copy Markdown
Member

Problem

MCP tool call payloads were the one activity type that skipped the wire projection — projectActivityPayload early-returned on itemType === "mcp_tool_call", so payload.data.item.result.content shipped the entire tool result. A single connector call (e.g. fetching a whole GitHub PR) reaches 1MB+, and one real MCP-heavy thread ships 11.7MB of mcp_tool_call payloads out of 17.8MB total wire size.

Fix

Run MCP payloads through the projection like every other tool payload. data.item is retained with a bounded shape: the call descriptor (tool, server, status, arguments, appContext, error, durationMs, type, id) survives intact, and item.result collapses to the same one-line preview that regular tool output already gets via summarizeToolTextOutput. data.toolCallId / data.kind are retained as before.

Both clients render data.item as JSON in the expanded work-log row and gate that row on data.item !== undefined, so an item record always projects to a record — the descriptor plus a result preview still renders. tool.started MCP rows go through the same path for consistency. Full payloads are untouched in SQLite and the event store; this only affects the wire.

Tests

Added to apps/server/test/ActivityPayloadProjection.test.ts: a 1MB+ result projects under 500 bytes while keeping tool/server/arguments/status, a small call keeps its fields, a failing call keeps error and isError, and an in-flight call with no result still renders. Full server suite green (1873 passed).


Changes made by Claude Fable 5 via Claude Code, running as a subagent of a planning session.

🤖 Generated with Claude Code


Note

Medium Risk
Changes orchestration wire payloads for a high-volume activity type; clients still get descriptors but lose full MCP result text in expanded work-log JSON unless they read persistence elsewhere.

Overview
MCP tool call activities are no longer exempt from wire projection.projectActivityPayload used to return them unchanged, so megabyte-scale result.content shipped on thread snapshots and activity events.

MCP rows now go through projectMcpToolCallData: call metadata (tool, server, status, arguments, error, durationMs, etc.) stays on data.item, while result is flattened from string or MCP text blocks (capped at 4KB) and collapsed to the same one-line preview other tools use via summarizeToolTextOutput. isError on failed tool results is preserved. In-flight calls without a result still expose a descriptor-only item so clients’ data.item !== undefined checks keep working.

Tests cover bounded megabyte payloads, failures, and in-progress calls; the web/mobile parity loop now excludes MCP because expanded work-log JSON will show the summarized result instead of the full blob. Persistence and the event store are unchanged—only API projection is affected.

Reviewed by Cursor Bugbot for commit 2ede711. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Bound MCP tool call payloads on the wire by projecting and summarizing large results

  • MCP tool call activities were previously passed through verbatim; they are now projected in ActivityPayloadProjection.ts to strip large result payloads down to a bounded summary.
  • Result content (string or MCP content blocks) is trimmed to 4096 characters via extractMcpResultText, then passed through summarizeToolTextOutput.
  • Only descriptor fields (type, id, tool, server, status, arguments, appContext, error, durationMs) are retained on the projected item; result is replaced with { content: summary } plus isError if the call failed.
  • Behavioral Change: MCP tool call activities no longer reach consumers with their raw result payloads; only the summarized content and descriptor fields are present.

Macroscope summarized 2ede711.

MCP tool call payloads skipped the wire projection entirely, so
`item.result.content` shipped whole tool results — a single connector
fetch reaches 1MB, and one MCP-heavy thread ships 11.7MB of
mcp_tool_call payloads out of 17.8MB total.
Project them like every other tool payload instead: keep the call
descriptor (tool, server, status, arguments, appContext, error,
durationMs, type, id) and collapse `result` to the same one-line
preview regular tool output already gets. Full payloads stay in SQLite.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 2a61d4fb-6ccb-4332-9b22-7821b8a2cf50

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Aug 6, 2026
@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved 2ede711

Straightforward performance fix that bounds MCP tool result payloads (which can reach megabytes) to prevent oversized wire payloads. Self-contained change with comprehensive test coverage, authored by the file's original creator.

You can customize Macroscope's approvability policy. Learn more.

@t3dotgg

Copy link
Copy Markdown
MemberAuthor

Superseded by #5482, which merged the same MCP payload bounding. Closing in favor of the merged implementation.

@t3dotggt3dotgg closed this Aug 6, 2026
@t3dotgg
t3dotgg deleted the t3code/slim-mcp-tool-payloads branch August 6, 2026 09:35
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(server): bound mcp tool payloads on the wire - #5481

Closed
t3dotgg wants to merge 1 commit into
mainfrom
t3code/slim-mcp-tool-payloads
Closed

fix(server): bound mcp tool payloads on the wire#5481
t3dotgg wants to merge 1 commit into
mainfrom
t3code/slim-mcp-tool-payloads

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 6, 2026

Copy link
Copy Markdown
Member

Problem

MCP tool call payloads were the one activity type that skipped the wire projection — projectActivityPayload early-returned on itemType === "mcp_tool_call", so payload.data.item.result.content shipped the entire tool result. A single connector call (e.g. fetching a whole GitHub PR) reaches 1MB+, and one real MCP-heavy thread ships 11.7MB of mcp_tool_call payloads out of 17.8MB total wire size.

Fix

Run MCP payloads through the projection like every other tool payload. data.item is retained with a bounded shape: the call descriptor (tool, server, status, arguments, appContext, error, durationMs, type, id) survives intact, and item.result collapses to the same one-line preview that regular tool output already gets via summarizeToolTextOutput. data.toolCallId / data.kind are retained as before.

Both clients render data.item as JSON in the expanded work-log row and gate that row on data.item !== undefined, so an item record always projects to a record — the descriptor plus a result preview still renders. tool.started MCP rows go through the same path for consistency. Full payloads are untouched in SQLite and the event store; this only affects the wire.

Tests

Added to apps/server/test/ActivityPayloadProjection.test.ts: a 1MB+ result projects under 500 bytes while keeping tool/server/arguments/status, a small call keeps its fields, a failing call keeps error and isError, and an in-flight call with no result still renders. Full server suite green (1873 passed).


Changes made by Claude Fable 5 via Claude Code, running as a subagent of a planning session.

🤖 Generated with Claude Code


Note

Medium Risk
Changes orchestration wire payloads for a high-volume activity type; clients still get descriptors but lose full MCP result text in expanded work-log JSON unless they read persistence elsewhere.

Overview
MCP tool call activities are no longer exempt from wire projection.projectActivityPayload used to return them unchanged, so megabyte-scale result.content shipped on thread snapshots and activity events.

MCP rows now go through projectMcpToolCallData: call metadata (tool, server, status, arguments, error, durationMs, etc.) stays on data.item, while result is flattened from string or MCP text blocks (capped at 4KB) and collapsed to the same one-line preview other tools use via summarizeToolTextOutput. isError on failed tool results is preserved. In-flight calls without a result still expose a descriptor-only item so clients’ data.item !== undefined checks keep working.

Tests cover bounded megabyte payloads, failures, and in-progress calls; the web/mobile parity loop now excludes MCP because expanded work-log JSON will show the summarized result instead of the full blob. Persistence and the event store are unchanged—only API projection is affected.

Reviewed by Cursor Bugbot for commit 2ede711. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Bound MCP tool call payloads on the wire by projecting and summarizing large results

  • MCP tool call activities were previously passed through verbatim; they are now projected in ActivityPayloadProjection.ts to strip large result payloads down to a bounded summary.
  • Result content (string or MCP content blocks) is trimmed to 4096 characters via extractMcpResultText, then passed through summarizeToolTextOutput.
  • Only descriptor fields (type, id, tool, server, status, arguments, appContext, error, durationMs) are retained on the projected item; result is replaced with { content: summary } plus isError if the call failed.
  • Behavioral Change: MCP tool call activities no longer reach consumers with their raw result payloads; only the summarized content and descriptor fields are present.

Macroscope summarized 2ede711.

MCP tool call payloads skipped the wire projection entirely, so
`item.result.content` shipped whole tool results — a single connector
fetch reaches 1MB, and one MCP-heavy thread ships 11.7MB of
mcp_tool_call payloads out of 17.8MB total.
Project them like every other tool payload instead: keep the call
descriptor (tool, server, status, arguments, appContext, error,
durationMs, type, id) and collapse `result` to the same one-line
preview regular tool output already gets. Full payloads stay in SQLite.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 2a61d4fb-6ccb-4332-9b22-7821b8a2cf50

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Aug 6, 2026
@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved 2ede711

Straightforward performance fix that bounds MCP tool result payloads (which can reach megabytes) to prevent oversized wire payloads. Self-contained change with comprehensive test coverage, authored by the file's original creator.

You can customize Macroscope's approvability policy. Learn more.

@t3dotgg

Copy link
Copy Markdown
MemberAuthor

Superseded by #5482, which merged the same MCP payload bounding. Closing in favor of the merged implementation.

@t3dotggt3dotgg closed this Aug 6, 2026
@t3dotgg
t3dotgg deleted the t3code/slim-mcp-tool-payloads branch August 6, 2026 09:35
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): bound mcp tool payloads on the wire - #5481

Closed
t3dotgg wants to merge 1 commit into
mainfrom
t3code/slim-mcp-tool-payloads
Closed

fix(server): bound mcp tool payloads on the wire#5481
t3dotgg wants to merge 1 commit into
mainfrom
t3code/slim-mcp-tool-payloads

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 6, 2026

Copy link
Copy Markdown
Member

Problem

MCP tool call payloads were the one activity type that skipped the wire projection — projectActivityPayload early-returned on itemType === "mcp_tool_call", so payload.data.item.result.content shipped the entire tool result. A single connector call (e.g. fetching a whole GitHub PR) reaches 1MB+, and one real MCP-heavy thread ships 11.7MB of mcp_tool_call payloads out of 17.8MB total wire size.

Fix

Run MCP payloads through the projection like every other tool payload. data.item is retained with a bounded shape: the call descriptor (tool, server, status, arguments, appContext, error, durationMs, type, id) survives intact, and item.result collapses to the same one-line preview that regular tool output already gets via summarizeToolTextOutput. data.toolCallId / data.kind are retained as before.

Both clients render data.item as JSON in the expanded work-log row and gate that row on data.item !== undefined, so an item record always projects to a record — the descriptor plus a result preview still renders. tool.started MCP rows go through the same path for consistency. Full payloads are untouched in SQLite and the event store; this only affects the wire.

Tests

Added to apps/server/test/ActivityPayloadProjection.test.ts: a 1MB+ result projects under 500 bytes while keeping tool/server/arguments/status, a small call keeps its fields, a failing call keeps error and isError, and an in-flight call with no result still renders. Full server suite green (1873 passed).


Changes made by Claude Fable 5 via Claude Code, running as a subagent of a planning session.

🤖 Generated with Claude Code


Note

Medium Risk
Changes orchestration wire payloads for a high-volume activity type; clients still get descriptors but lose full MCP result text in expanded work-log JSON unless they read persistence elsewhere.

Overview
MCP tool call activities are no longer exempt from wire projection.projectActivityPayload used to return them unchanged, so megabyte-scale result.content shipped on thread snapshots and activity events.

MCP rows now go through projectMcpToolCallData: call metadata (tool, server, status, arguments, error, durationMs, etc.) stays on data.item, while result is flattened from string or MCP text blocks (capped at 4KB) and collapsed to the same one-line preview other tools use via summarizeToolTextOutput. isError on failed tool results is preserved. In-flight calls without a result still expose a descriptor-only item so clients’ data.item !== undefined checks keep working.

Tests cover bounded megabyte payloads, failures, and in-progress calls; the web/mobile parity loop now excludes MCP because expanded work-log JSON will show the summarized result instead of the full blob. Persistence and the event store are unchanged—only API projection is affected.

Reviewed by Cursor Bugbot for commit 2ede711. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Bound MCP tool call payloads on the wire by projecting and summarizing large results

  • MCP tool call activities were previously passed through verbatim; they are now projected in ActivityPayloadProjection.ts to strip large result payloads down to a bounded summary.
  • Result content (string or MCP content blocks) is trimmed to 4096 characters via extractMcpResultText, then passed through summarizeToolTextOutput.
  • Only descriptor fields (type, id, tool, server, status, arguments, appContext, error, durationMs) are retained on the projected item; result is replaced with { content: summary } plus isError if the call failed.
  • Behavioral Change: MCP tool call activities no longer reach consumers with their raw result payloads; only the summarized content and descriptor fields are present.

Macroscope summarized 2ede711.

MCP tool call payloads skipped the wire projection entirely, so
`item.result.content` shipped whole tool results — a single connector
fetch reaches 1MB, and one MCP-heavy thread ships 11.7MB of
mcp_tool_call payloads out of 17.8MB total.
Project them like every other tool payload instead: keep the call
descriptor (tool, server, status, arguments, appContext, error,
durationMs, type, id) and collapse `result` to the same one-line
preview regular tool output already gets. Full payloads stay in SQLite.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 2a61d4fb-6ccb-4332-9b22-7821b8a2cf50

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Aug 6, 2026
@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved 2ede711

Straightforward performance fix that bounds MCP tool result payloads (which can reach megabytes) to prevent oversized wire payloads. Self-contained change with comprehensive test coverage, authored by the file's original creator.

You can customize Macroscope's approvability policy. Learn more.

@t3dotgg

Copy link
Copy Markdown
MemberAuthor

Superseded by #5482, which merged the same MCP payload bounding. Closing in favor of the merged implementation.

@t3dotggt3dotgg closed this Aug 6, 2026
@t3dotgg
t3dotgg deleted the t3code/slim-mcp-tool-payloads branch August 6, 2026 09:35
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): bound mcp tool payloads on the wire - #5481

Closed
t3dotgg wants to merge 1 commit into
mainfrom
t3code/slim-mcp-tool-payloads
Closed

fix(server): bound mcp tool payloads on the wire#5481
t3dotgg wants to merge 1 commit into
mainfrom
t3code/slim-mcp-tool-payloads

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 6, 2026

Copy link
Copy Markdown
Member

Problem

MCP tool call payloads were the one activity type that skipped the wire projection — projectActivityPayload early-returned on itemType === "mcp_tool_call", so payload.data.item.result.content shipped the entire tool result. A single connector call (e.g. fetching a whole GitHub PR) reaches 1MB+, and one real MCP-heavy thread ships 11.7MB of mcp_tool_call payloads out of 17.8MB total wire size.

Fix

Run MCP payloads through the projection like every other tool payload. data.item is retained with a bounded shape: the call descriptor (tool, server, status, arguments, appContext, error, durationMs, type, id) survives intact, and item.result collapses to the same one-line preview that regular tool output already gets via summarizeToolTextOutput. data.toolCallId / data.kind are retained as before.

Both clients render data.item as JSON in the expanded work-log row and gate that row on data.item !== undefined, so an item record always projects to a record — the descriptor plus a result preview still renders. tool.started MCP rows go through the same path for consistency. Full payloads are untouched in SQLite and the event store; this only affects the wire.

Tests

Added to apps/server/test/ActivityPayloadProjection.test.ts: a 1MB+ result projects under 500 bytes while keeping tool/server/arguments/status, a small call keeps its fields, a failing call keeps error and isError, and an in-flight call with no result still renders. Full server suite green (1873 passed).


Changes made by Claude Fable 5 via Claude Code, running as a subagent of a planning session.

🤖 Generated with Claude Code


Note

Medium Risk
Changes orchestration wire payloads for a high-volume activity type; clients still get descriptors but lose full MCP result text in expanded work-log JSON unless they read persistence elsewhere.

Overview
MCP tool call activities are no longer exempt from wire projection.projectActivityPayload used to return them unchanged, so megabyte-scale result.content shipped on thread snapshots and activity events.

MCP rows now go through projectMcpToolCallData: call metadata (tool, server, status, arguments, error, durationMs, etc.) stays on data.item, while result is flattened from string or MCP text blocks (capped at 4KB) and collapsed to the same one-line preview other tools use via summarizeToolTextOutput. isError on failed tool results is preserved. In-flight calls without a result still expose a descriptor-only item so clients’ data.item !== undefined checks keep working.

Tests cover bounded megabyte payloads, failures, and in-progress calls; the web/mobile parity loop now excludes MCP because expanded work-log JSON will show the summarized result instead of the full blob. Persistence and the event store are unchanged—only API projection is affected.

Reviewed by Cursor Bugbot for commit 2ede711. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Bound MCP tool call payloads on the wire by projecting and summarizing large results

  • MCP tool call activities were previously passed through verbatim; they are now projected in ActivityPayloadProjection.ts to strip large result payloads down to a bounded summary.
  • Result content (string or MCP content blocks) is trimmed to 4096 characters via extractMcpResultText, then passed through summarizeToolTextOutput.
  • Only descriptor fields (type, id, tool, server, status, arguments, appContext, error, durationMs) are retained on the projected item; result is replaced with { content: summary } plus isError if the call failed.
  • Behavioral Change: MCP tool call activities no longer reach consumers with their raw result payloads; only the summarized content and descriptor fields are present.

Macroscope summarized 2ede711.

MCP tool call payloads skipped the wire projection entirely, so
`item.result.content` shipped whole tool results — a single connector
fetch reaches 1MB, and one MCP-heavy thread ships 11.7MB of
mcp_tool_call payloads out of 17.8MB total.
Project them like every other tool payload instead: keep the call
descriptor (tool, server, status, arguments, appContext, error,
durationMs, type, id) and collapse `result` to the same one-line
preview regular tool output already gets. Full payloads stay in SQLite.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 2a61d4fb-6ccb-4332-9b22-7821b8a2cf50

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Aug 6, 2026
@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved 2ede711

Straightforward performance fix that bounds MCP tool result payloads (which can reach megabytes) to prevent oversized wire payloads. Self-contained change with comprehensive test coverage, authored by the file's original creator.

You can customize Macroscope's approvability policy. Learn more.

@t3dotgg

Copy link
Copy Markdown
MemberAuthor

Superseded by #5482, which merged the same MCP payload bounding. Closing in favor of the merged implementation.

@t3dotggt3dotgg closed this Aug 6, 2026
@t3dotgg
t3dotgg deleted the t3code/slim-mcp-tool-payloads branch August 6, 2026 09:35
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(server): bound mcp tool payloads on the wire - #5481

Closed
t3dotgg wants to merge 1 commit into
mainfrom
t3code/slim-mcp-tool-payloads
Closed

fix(server): bound mcp tool payloads on the wire#5481
t3dotgg wants to merge 1 commit into
mainfrom
t3code/slim-mcp-tool-payloads

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 6, 2026

Copy link
Copy Markdown
Member

Problem

MCP tool call payloads were the one activity type that skipped the wire projection — projectActivityPayload early-returned on itemType === "mcp_tool_call", so payload.data.item.result.content shipped the entire tool result. A single connector call (e.g. fetching a whole GitHub PR) reaches 1MB+, and one real MCP-heavy thread ships 11.7MB of mcp_tool_call payloads out of 17.8MB total wire size.

Fix

Run MCP payloads through the projection like every other tool payload. data.item is retained with a bounded shape: the call descriptor (tool, server, status, arguments, appContext, error, durationMs, type, id) survives intact, and item.result collapses to the same one-line preview that regular tool output already gets via summarizeToolTextOutput. data.toolCallId / data.kind are retained as before.

Both clients render data.item as JSON in the expanded work-log row and gate that row on data.item !== undefined, so an item record always projects to a record — the descriptor plus a result preview still renders. tool.started MCP rows go through the same path for consistency. Full payloads are untouched in SQLite and the event store; this only affects the wire.

Tests

Added to apps/server/test/ActivityPayloadProjection.test.ts: a 1MB+ result projects under 500 bytes while keeping tool/server/arguments/status, a small call keeps its fields, a failing call keeps error and isError, and an in-flight call with no result still renders. Full server suite green (1873 passed).


Changes made by Claude Fable 5 via Claude Code, running as a subagent of a planning session.

🤖 Generated with Claude Code


Note

Medium Risk
Changes orchestration wire payloads for a high-volume activity type; clients still get descriptors but lose full MCP result text in expanded work-log JSON unless they read persistence elsewhere.

Overview
MCP tool call activities are no longer exempt from wire projection.projectActivityPayload used to return them unchanged, so megabyte-scale result.content shipped on thread snapshots and activity events.

MCP rows now go through projectMcpToolCallData: call metadata (tool, server, status, arguments, error, durationMs, etc.) stays on data.item, while result is flattened from string or MCP text blocks (capped at 4KB) and collapsed to the same one-line preview other tools use via summarizeToolTextOutput. isError on failed tool results is preserved. In-flight calls without a result still expose a descriptor-only item so clients’ data.item !== undefined checks keep working.

Tests cover bounded megabyte payloads, failures, and in-progress calls; the web/mobile parity loop now excludes MCP because expanded work-log JSON will show the summarized result instead of the full blob. Persistence and the event store are unchanged—only API projection is affected.

Reviewed by Cursor Bugbot for commit 2ede711. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Bound MCP tool call payloads on the wire by projecting and summarizing large results

  • MCP tool call activities were previously passed through verbatim; they are now projected in ActivityPayloadProjection.ts to strip large result payloads down to a bounded summary.
  • Result content (string or MCP content blocks) is trimmed to 4096 characters via extractMcpResultText, then passed through summarizeToolTextOutput.
  • Only descriptor fields (type, id, tool, server, status, arguments, appContext, error, durationMs) are retained on the projected item; result is replaced with { content: summary } plus isError if the call failed.
  • Behavioral Change: MCP tool call activities no longer reach consumers with their raw result payloads; only the summarized content and descriptor fields are present.

Macroscope summarized 2ede711.

MCP tool call payloads skipped the wire projection entirely, so
`item.result.content` shipped whole tool results — a single connector
fetch reaches 1MB, and one MCP-heavy thread ships 11.7MB of
mcp_tool_call payloads out of 17.8MB total.
Project them like every other tool payload instead: keep the call
descriptor (tool, server, status, arguments, appContext, error,
durationMs, type, id) and collapse `result` to the same one-line
preview regular tool output already gets. Full payloads stay in SQLite.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 2a61d4fb-6ccb-4332-9b22-7821b8a2cf50

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Aug 6, 2026
@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved 2ede711

Straightforward performance fix that bounds MCP tool result payloads (which can reach megabytes) to prevent oversized wire payloads. Self-contained change with comprehensive test coverage, authored by the file's original creator.

You can customize Macroscope's approvability policy. Learn more.

@t3dotgg

Copy link
Copy Markdown
MemberAuthor

Superseded by #5482, which merged the same MCP payload bounding. Closing in favor of the merged implementation.

@t3dotggt3dotgg closed this Aug 6, 2026
@t3dotgg
t3dotgg deleted the t3code/slim-mcp-tool-payloads branch August 6, 2026 09:35
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): bound mcp tool payloads on the wire - #5481

Closed
t3dotgg wants to merge 1 commit into
mainfrom
t3code/slim-mcp-tool-payloads
Closed

fix(server): bound mcp tool payloads on the wire#5481
t3dotgg wants to merge 1 commit into
mainfrom
t3code/slim-mcp-tool-payloads

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 6, 2026

Copy link
Copy Markdown
Member

Problem

MCP tool call payloads were the one activity type that skipped the wire projection — projectActivityPayload early-returned on itemType === "mcp_tool_call", so payload.data.item.result.content shipped the entire tool result. A single connector call (e.g. fetching a whole GitHub PR) reaches 1MB+, and one real MCP-heavy thread ships 11.7MB of mcp_tool_call payloads out of 17.8MB total wire size.

Fix

Run MCP payloads through the projection like every other tool payload. data.item is retained with a bounded shape: the call descriptor (tool, server, status, arguments, appContext, error, durationMs, type, id) survives intact, and item.result collapses to the same one-line preview that regular tool output already gets via summarizeToolTextOutput. data.toolCallId / data.kind are retained as before.

Both clients render data.item as JSON in the expanded work-log row and gate that row on data.item !== undefined, so an item record always projects to a record — the descriptor plus a result preview still renders. tool.started MCP rows go through the same path for consistency. Full payloads are untouched in SQLite and the event store; this only affects the wire.

Tests

Added to apps/server/test/ActivityPayloadProjection.test.ts: a 1MB+ result projects under 500 bytes while keeping tool/server/arguments/status, a small call keeps its fields, a failing call keeps error and isError, and an in-flight call with no result still renders. Full server suite green (1873 passed).


Changes made by Claude Fable 5 via Claude Code, running as a subagent of a planning session.

🤖 Generated with Claude Code


Note

Medium Risk
Changes orchestration wire payloads for a high-volume activity type; clients still get descriptors but lose full MCP result text in expanded work-log JSON unless they read persistence elsewhere.

Overview
MCP tool call activities are no longer exempt from wire projection.projectActivityPayload used to return them unchanged, so megabyte-scale result.content shipped on thread snapshots and activity events.

MCP rows now go through projectMcpToolCallData: call metadata (tool, server, status, arguments, error, durationMs, etc.) stays on data.item, while result is flattened from string or MCP text blocks (capped at 4KB) and collapsed to the same one-line preview other tools use via summarizeToolTextOutput. isError on failed tool results is preserved. In-flight calls without a result still expose a descriptor-only item so clients’ data.item !== undefined checks keep working.

Tests cover bounded megabyte payloads, failures, and in-progress calls; the web/mobile parity loop now excludes MCP because expanded work-log JSON will show the summarized result instead of the full blob. Persistence and the event store are unchanged—only API projection is affected.

Reviewed by Cursor Bugbot for commit 2ede711. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Bound MCP tool call payloads on the wire by projecting and summarizing large results

  • MCP tool call activities were previously passed through verbatim; they are now projected in ActivityPayloadProjection.ts to strip large result payloads down to a bounded summary.
  • Result content (string or MCP content blocks) is trimmed to 4096 characters via extractMcpResultText, then passed through summarizeToolTextOutput.
  • Only descriptor fields (type, id, tool, server, status, arguments, appContext, error, durationMs) are retained on the projected item; result is replaced with { content: summary } plus isError if the call failed.
  • Behavioral Change: MCP tool call activities no longer reach consumers with their raw result payloads; only the summarized content and descriptor fields are present.

Macroscope summarized 2ede711.

MCP tool call payloads skipped the wire projection entirely, so
`item.result.content` shipped whole tool results — a single connector
fetch reaches 1MB, and one MCP-heavy thread ships 11.7MB of
mcp_tool_call payloads out of 17.8MB total.
Project them like every other tool payload instead: keep the call
descriptor (tool, server, status, arguments, appContext, error,
durationMs, type, id) and collapse `result` to the same one-line
preview regular tool output already gets. Full payloads stay in SQLite.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 2a61d4fb-6ccb-4332-9b22-7821b8a2cf50

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Aug 6, 2026
@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved 2ede711

Straightforward performance fix that bounds MCP tool result payloads (which can reach megabytes) to prevent oversized wire payloads. Self-contained change with comprehensive test coverage, authored by the file's original creator.

You can customize Macroscope's approvability policy. Learn more.

@t3dotgg

Copy link
Copy Markdown
MemberAuthor

Superseded by #5482, which merged the same MCP payload bounding. Closing in favor of the merged implementation.

@t3dotggt3dotgg closed this Aug 6, 2026
@t3dotgg
t3dotgg deleted the t3code/slim-mcp-tool-payloads branch August 6, 2026 09:35
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): bound mcp tool payloads on the wire - #5481

Closed
t3dotgg wants to merge 1 commit into
mainfrom
t3code/slim-mcp-tool-payloads
Closed

fix(server): bound mcp tool payloads on the wire#5481
t3dotgg wants to merge 1 commit into
mainfrom
t3code/slim-mcp-tool-payloads

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 6, 2026

Copy link
Copy Markdown
Member

Problem

MCP tool call payloads were the one activity type that skipped the wire projection — projectActivityPayload early-returned on itemType === "mcp_tool_call", so payload.data.item.result.content shipped the entire tool result. A single connector call (e.g. fetching a whole GitHub PR) reaches 1MB+, and one real MCP-heavy thread ships 11.7MB of mcp_tool_call payloads out of 17.8MB total wire size.

Fix

Run MCP payloads through the projection like every other tool payload. data.item is retained with a bounded shape: the call descriptor (tool, server, status, arguments, appContext, error, durationMs, type, id) survives intact, and item.result collapses to the same one-line preview that regular tool output already gets via summarizeToolTextOutput. data.toolCallId / data.kind are retained as before.

Both clients render data.item as JSON in the expanded work-log row and gate that row on data.item !== undefined, so an item record always projects to a record — the descriptor plus a result preview still renders. tool.started MCP rows go through the same path for consistency. Full payloads are untouched in SQLite and the event store; this only affects the wire.

Tests

Added to apps/server/test/ActivityPayloadProjection.test.ts: a 1MB+ result projects under 500 bytes while keeping tool/server/arguments/status, a small call keeps its fields, a failing call keeps error and isError, and an in-flight call with no result still renders. Full server suite green (1873 passed).


Changes made by Claude Fable 5 via Claude Code, running as a subagent of a planning session.

🤖 Generated with Claude Code


Note

Medium Risk
Changes orchestration wire payloads for a high-volume activity type; clients still get descriptors but lose full MCP result text in expanded work-log JSON unless they read persistence elsewhere.

Overview
MCP tool call activities are no longer exempt from wire projection.projectActivityPayload used to return them unchanged, so megabyte-scale result.content shipped on thread snapshots and activity events.

MCP rows now go through projectMcpToolCallData: call metadata (tool, server, status, arguments, error, durationMs, etc.) stays on data.item, while result is flattened from string or MCP text blocks (capped at 4KB) and collapsed to the same one-line preview other tools use via summarizeToolTextOutput. isError on failed tool results is preserved. In-flight calls without a result still expose a descriptor-only item so clients’ data.item !== undefined checks keep working.

Tests cover bounded megabyte payloads, failures, and in-progress calls; the web/mobile parity loop now excludes MCP because expanded work-log JSON will show the summarized result instead of the full blob. Persistence and the event store are unchanged—only API projection is affected.

Reviewed by Cursor Bugbot for commit 2ede711. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Bound MCP tool call payloads on the wire by projecting and summarizing large results

  • MCP tool call activities were previously passed through verbatim; they are now projected in ActivityPayloadProjection.ts to strip large result payloads down to a bounded summary.
  • Result content (string or MCP content blocks) is trimmed to 4096 characters via extractMcpResultText, then passed through summarizeToolTextOutput.
  • Only descriptor fields (type, id, tool, server, status, arguments, appContext, error, durationMs) are retained on the projected item; result is replaced with { content: summary } plus isError if the call failed.
  • Behavioral Change: MCP tool call activities no longer reach consumers with their raw result payloads; only the summarized content and descriptor fields are present.

Macroscope summarized 2ede711.

MCP tool call payloads skipped the wire projection entirely, so
`item.result.content` shipped whole tool results — a single connector
fetch reaches 1MB, and one MCP-heavy thread ships 11.7MB of
mcp_tool_call payloads out of 17.8MB total.
Project them like every other tool payload instead: keep the call
descriptor (tool, server, status, arguments, appContext, error,
durationMs, type, id) and collapse `result` to the same one-line
preview regular tool output already gets. Full payloads stay in SQLite.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 2a61d4fb-6ccb-4332-9b22-7821b8a2cf50

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Aug 6, 2026
@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved 2ede711

Straightforward performance fix that bounds MCP tool result payloads (which can reach megabytes) to prevent oversized wire payloads. Self-contained change with comprehensive test coverage, authored by the file's original creator.

You can customize Macroscope's approvability policy. Learn more.

@t3dotgg

Copy link
Copy Markdown
MemberAuthor

Superseded by #5482, which merged the same MCP payload bounding. Closing in favor of the merged implementation.

@t3dotggt3dotgg closed this Aug 6, 2026
@t3dotgg
t3dotgg deleted the t3code/slim-mcp-tool-payloads branch August 6, 2026 09:35
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(server): bound mcp tool payloads on the wire - #5481

Closed
t3dotgg wants to merge 1 commit into
mainfrom
t3code/slim-mcp-tool-payloads
Closed

fix(server): bound mcp tool payloads on the wire#5481
t3dotgg wants to merge 1 commit into
mainfrom
t3code/slim-mcp-tool-payloads

Conversation

@t3dotgg

@t3dotggt3dotgg commented Aug 6, 2026

Copy link
Copy Markdown
Member

Problem

MCP tool call payloads were the one activity type that skipped the wire projection — projectActivityPayload early-returned on itemType === "mcp_tool_call", so payload.data.item.result.content shipped the entire tool result. A single connector call (e.g. fetching a whole GitHub PR) reaches 1MB+, and one real MCP-heavy thread ships 11.7MB of mcp_tool_call payloads out of 17.8MB total wire size.

Fix

Run MCP payloads through the projection like every other tool payload. data.item is retained with a bounded shape: the call descriptor (tool, server, status, arguments, appContext, error, durationMs, type, id) survives intact, and item.result collapses to the same one-line preview that regular tool output already gets via summarizeToolTextOutput. data.toolCallId / data.kind are retained as before.

Both clients render data.item as JSON in the expanded work-log row and gate that row on data.item !== undefined, so an item record always projects to a record — the descriptor plus a result preview still renders. tool.started MCP rows go through the same path for consistency. Full payloads are untouched in SQLite and the event store; this only affects the wire.

Tests

Added to apps/server/test/ActivityPayloadProjection.test.ts: a 1MB+ result projects under 500 bytes while keeping tool/server/arguments/status, a small call keeps its fields, a failing call keeps error and isError, and an in-flight call with no result still renders. Full server suite green (1873 passed).


Changes made by Claude Fable 5 via Claude Code, running as a subagent of a planning session.

🤖 Generated with Claude Code


Note

Medium Risk
Changes orchestration wire payloads for a high-volume activity type; clients still get descriptors but lose full MCP result text in expanded work-log JSON unless they read persistence elsewhere.

Overview
MCP tool call activities are no longer exempt from wire projection.projectActivityPayload used to return them unchanged, so megabyte-scale result.content shipped on thread snapshots and activity events.

MCP rows now go through projectMcpToolCallData: call metadata (tool, server, status, arguments, error, durationMs, etc.) stays on data.item, while result is flattened from string or MCP text blocks (capped at 4KB) and collapsed to the same one-line preview other tools use via summarizeToolTextOutput. isError on failed tool results is preserved. In-flight calls without a result still expose a descriptor-only item so clients’ data.item !== undefined checks keep working.

Tests cover bounded megabyte payloads, failures, and in-progress calls; the web/mobile parity loop now excludes MCP because expanded work-log JSON will show the summarized result instead of the full blob. Persistence and the event store are unchanged—only API projection is affected.

Reviewed by Cursor Bugbot for commit 2ede711. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Bound MCP tool call payloads on the wire by projecting and summarizing large results

  • MCP tool call activities were previously passed through verbatim; they are now projected in ActivityPayloadProjection.ts to strip large result payloads down to a bounded summary.
  • Result content (string or MCP content blocks) is trimmed to 4096 characters via extractMcpResultText, then passed through summarizeToolTextOutput.
  • Only descriptor fields (type, id, tool, server, status, arguments, appContext, error, durationMs) are retained on the projected item; result is replaced with { content: summary } plus isError if the call failed.
  • Behavioral Change: MCP tool call activities no longer reach consumers with their raw result payloads; only the summarized content and descriptor fields are present.

Macroscope summarized 2ede711.

MCP tool call payloads skipped the wire projection entirely, so
`item.result.content` shipped whole tool results — a single connector
fetch reaches 1MB, and one MCP-heavy thread ships 11.7MB of
mcp_tool_call payloads out of 17.8MB total.
Project them like every other tool payload instead: keep the call
descriptor (tool, server, status, arguments, appContext, error,
durationMs, type, id) and collapse `result` to the same one-line
preview regular tool output already gets. Full payloads stay in SQLite.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 2a61d4fb-6ccb-4332-9b22-7821b8a2cf50

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Aug 6, 2026
@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved 2ede711

Straightforward performance fix that bounds MCP tool result payloads (which can reach megabytes) to prevent oversized wire payloads. Self-contained change with comprehensive test coverage, authored by the file's original creator.

You can customize Macroscope's approvability policy. Learn more.

@t3dotgg

Copy link
Copy Markdown
MemberAuthor

Superseded by #5482, which merged the same MCP payload bounding. Closing in favor of the merged implementation.

@t3dotggt3dotgg closed this Aug 6, 2026
@t3dotgg
t3dotgg deleted the t3code/slim-mcp-tool-payloads branch August 6, 2026 09:35
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@t3dotgg