Skip to content

Source connector: MCP server #100

Description

@ocularminds

What

A SignalConnector for MCP server (kind MCP), so an operator can add it on the Signal sources page, collect from it, and forward what it yields to the Decionis Protocol. Plan: docs/SignalConnectors.md (S3); the framework (interface, registry, demo connectors, the Sources page, forwarding) is already in infra/connectors/ and application/signals/.

Configure an MCP server by URL or command, list its tools and resources on the Sources page, and map a tool result or a resource to signals with a small declarative mapping. Steward remains an MCP client only and exposes no MCP server of its own. The reference client is @modelcontextprotocol/sdk (MIT).

Scope

  • infra/connectors/McpConnector.ts implementing SignalConnector: source (never a credential in it) and collect() returning CapturedSignal[] parsed through CapturedSignalSchema.
  • Configuration for the source: target, credential reference, and any mapping the connector needs; credentials are read on the server at the moment of use and never serialised.
  • Egress: the connector reaches only the host its configuration names; a test proves a different host is refused.
  • A demo fixture for the connector following the fixture conventions, so demo mode shows it.
  • Tests for the mapping into CapturedSignal, for the egress rule, and for the failure path (source down: reported, not stored, nothing fabricated).
  • A row in the connector catalogue in docs/SignalConnectors.md, a paragraph in docs/Docker.md on configuring it, and the threat-model note if the connector adds an asset.

Done when

  • The source appears on /signals, "Collect now" yields signals that forward and report their count, and a wrong credential or host produces a clear error with nothing stored.
  • Any new dependency passes pnpm licenses:check.

How to pick this up

  • Comment on this issue so nobody else starts it, then branch from master with one branch per issue; the bot opens the pull request when you push.
  • Follow CONTRIBUTING.md: pnpm verify green, every commit signed off with -s (DCO), no telemetry, no dependency outside the license policy in scripts/CheckLicensePolicy.mjs.
  • Fixtures and samples follow the demo conventions: organisations from the NATO alphabet, people surnamed Example, references shaped CRM-DEMO-000n, no real host, email, phone or URL. The tests enforce it.
  • Update the documents that make a claim about what you changed in the same pull request: README, the Docker guide, ThreatModel, and the discovery files public/llms*.txt (with pnpm discovery).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

connector: sourceA signal-source connector (docs/SignalConnectors.md)help wantedExtra attention is needed

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions