Skip to content

feat(mcp): add native result previews and interactive apps - #8786

Open
waleedlatif1 wants to merge 7 commits into
stagingfrom
codex/native-mcp-results
Open

waleedlatif1 wants to merge 7 commits into
stagingfrom
codex/native-mcp-results

Conversation

@waleedlatif1

@waleedlatif1 waleedlatif1 commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Show MCP images, audio, and files as native chat cards and persistent preview tabs. Preserve immutable results across transcript reloads and chat forks.
  • Host interactive MCP Apps with sandboxed frames, declared network policies, theme updates, and tool/resource calls authorized against the originating connection.
  • Preserve embedded text reports and MCP UI metadata while keeping private App data and resolved credentials out of model output. Recheck ownership and current connection access for live App operations; redact encoded and rotating OAuth credential echoes before delivery. Capture linked files during execution so historical previews remain stable after a connection is disabled.

Type of Change

  • New feature

Testing

  • 64 integration checks against disposable Postgres, Redis, local file storage, and a real MCP HTTP server.
  • Eleven browser checks in each of Chromium and WebKit using the MCP Apps SDK and production React components: handshake, sandbox isolation, declared network policy, opaque-frame source validation, close/reopen, binary readiness, Office rendering, and video/audio playback.
  • 71 focused MCP application tests; all 386 root script tests and 20 workspace test tasks (36,748 Sim tests); lint; root type-check; all 58 repository audits; workflow lint; docs manifest and block registry checks.
  • Verified the official Excalidraw MCP App through the full running Next.js app: real remote tool execution, persisted results, declared CDN assets, and an inline diagram. HTTP checks failed before the CSP fix and passed afterward. This run did not verify AI chat orchestration or fullscreen editing.
  • Drizzle reports no schema changes; migration safety check passes. Browser and integration suites emit JSON reports, with a browser screenshot.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@waleedlatif1
waleedlatif1 requested a review from a team as a code owner October 8, 2026 05:58
@vercel

vercel Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 8, 2026 8:53pm UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 68 files

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/mcp/app-frame.ts Outdated
Comment thread .github/workflows/checks.yml Outdated
Comment thread apps/sim/lib/mcp/presentation-storage.ts
Comment thread apps/sim/app/api/mothership/chats/[chatId]/mcp-results/[id]/frame/route.ts Outdated
Comment thread apps/sim/lib/mcp/service.ts Outdated
Comment thread apps/sim/lib/mcp/presentation.ts
Comment thread apps/sim/app/workspace/[workspaceId]/home/hooks/stream/handle-tool-event.ts Outdated
@greptile-apps

greptile-apps Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[High impact] The PR appears safe to merge; no actionable issue remains from this re-review.

Summary

Adds native MCP result cards, saved preview tabs, and interactive Apps.

  • Saves attachment bytes for transcript reloads and chat forks.
  • Keeps private App data out of model output and removes credential echoes before delivery.
  • Checks chat ownership and current connection access for live App calls.
  • Since the last review, only the declaration-only executeTool test was removed. The real App execution checks remain.
  • The previous unnumbered findings are addressed. No new actionable issue was found.

Diagram

sequenceDiagram
    participant Tool as MCP tool
    participant Server as Sim server
    participant Storage as Saved results
    participant Chat as Chat
    participant App as Sandboxed App
    Tool->>Server: Result and linked files
    Server->>Server: Remove credential echoes
    Server->>Storage: Save immutable result
    Server->>Chat: Text and display receipt
    Chat->>Server: Open attachment or App
    Server->>Server: Check chat ownership
    Storage-->>Server: Saved result
    Server-->>Chat: Attachment bytes
    Server-->>App: Private App result
    App->>Server: Tool or resource request
    Server->>Server: Check current connection access
    Server->>Tool: Authorized request
Loading

Reviews (8) · Last reviewed commit: "chore(mcp): remove redundant operation d..." · Reviewed by Greptile

Comment thread apps/sim/lib/internal/mcp/presentation.ts Outdated
Comment thread apps/sim/lib/mothership/chat/application/mcp-results.ts
Comment thread apps/sim/lib/api/contracts/mcp-presentations.ts Outdated
@waleedlatif1
waleedlatif1 force-pushed the codex/native-mcp-results branch from d0e5107 to e0b1573 Compare October 8, 2026 06:55
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 74 files

Confidence score: 2/5

  • In apps/sim/lib/mcp/app-frame.ts, split-horizon DNS can make a hostname pass validation while resolving to a private IP, allowing the generated CSP to authorize requests to a LAN host. Enforce the private-address restriction on the resolved destination.
Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="apps/sim/lib/mcp/app-frame.ts">

<violation number="1" location="apps/sim/lib/mcp/app-frame.ts:19">
P1: A split-horizon hostname can pass this check while resolving to a private IP, after which the generated CSP authorizes App requests to that LAN host. Enforce the private-address restriction against resolved destinations, not only hostname text.</violation>
</file>

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

if (url.protocol === 'wss:' && !allowWebSocket)
throw new OrchestrationError('validation', 'Static App resources require HTTPS')
const hostname = url.hostname.replace(/\.$/, '')
if (hostname === 'localhost' || hostname.endsWith('.localhost') || /^[\d.]+$/.test(hostname))

@cubic-dev-ai cubic-dev-ai Bot Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1: A split-horizon hostname can pass this check while resolving to a private IP, after which the generated CSP authorizes App requests to that LAN host. Enforce the private-address restriction against resolved destinations, not only hostname text.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. At apps/sim/lib/mcp/app-frame.ts, line 19:

<comment>A split-horizon hostname can pass this check while resolving to a private IP, after which the generated CSP authorizes App requests to that LAN host. Enforce the private-address restriction against resolved destinations, not only hostname text.</comment>

<file context>
@@ -0,0 +1,79 @@
+    if (url.protocol === 'wss:' && !allowWebSocket)
+      throw new OrchestrationError('validation', 'Static App resources require HTTPS')
+    const hostname = url.hostname.replace(/\.$/, '')
+    if (hostname === 'localhost' || hostname.endsWith('.localhost') || /^[\d.]+$/.test(hostname))
+      throw new OrchestrationError('validation', 'MCP Apps cannot access local network addresses')
+    return domain
</file context>
Fix with cubic

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Confirmed: the hostname check is not destination-IP isolation. A server-side DNS preflight cannot pin the address used by the browser, so it would not close split-horizon DNS or rebinding across browser engines. Leaving this thread open while the App networking policy is finalized; the current implementation does not guarantee that declared HTTPS origins cannot reach a private network.

Comment thread apps/sim/lib/mcp/encoded-content.ts Outdated
Comment thread apps/sim/lib/credentials/application/operations.ts
Comment thread apps/sim/lib/mothership/chat/application/mcp-results.ts Outdated
Comment thread apps/sim/scripts/test-mcp-app-e2e.ts Outdated
Comment thread apps/sim/lib/mcp/service.ts Outdated
Comment thread apps/sim/lib/mothership/chat/application/mcp-results.ts
Comment thread apps/sim/lib/mothership/chat/application/mcp-results.ts Outdated
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 82 files

Confidence score: 4/5

  • The message injections in apps/sim/scripts/test-mcp-app-e2e.ts don’t verify the event.source guard: the proxy targets itself, and the host message has a different origin from the sandboxed app. Adjust the fixtures to isolate the source check; an origin-only check could pass these tests.
Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="apps/sim/scripts/test-mcp-app-e2e.ts">

<violation number="1" location="apps/sim/scripts/test-mcp-app-e2e.ts:298">
P2: These injections do not verify the `event.source` guard: the proxy message targets itself, and the host message has a different origin from the sandboxed app. An origin-only check would pass while accepting messages from another opaque-origin frame; send the forged RPC from a second sandboxed frame and assert that no tool call occurs.</violation>
</file>

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/internal/mcp/presentation.ts Outdated
Comment thread apps/sim/lib/mcp/application/read-resource.ts
Comment thread apps/sim/lib/sim-search/live/managed-mcp.integration.ts
Comment thread apps/sim/lib/mcp/application/execute-managed-tool.ts Outdated
Comment thread apps/sim/scripts/test-mcp-app-e2e.ts Outdated
Comment thread apps/sim/lib/mcp/presentation-storage.ts Outdated
Comment thread apps/sim/lib/mcp/application/execute-tool.ts Outdated
@waleedlatif1
waleedlatif1 force-pushed the codex/native-mcp-results branch from 12c6c28 to 027adbc Compare October 8, 2026 08:53
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 83 files

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/internal/mcp/presentation.ts Outdated
Comment thread apps/sim/scripts/test-mcp-app-e2e.ts Outdated
Comment thread apps/sim/lib/mcp/presentation-storage.ts
Comment thread apps/sim/lib/mcp/encoded-content.ts
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 83 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

@waleedlatif1
waleedlatif1 force-pushed the codex/native-mcp-results branch from 69029ee to 79d39e7 Compare October 8, 2026 16:08
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 84 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

@waleedlatif1
waleedlatif1 force-pushed the codex/native-mcp-results branch from 79d39e7 to ad03e77 Compare October 8, 2026 20:25
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 84 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

Comment thread apps/sim/lib/mcp/application/operations.test.ts Outdated
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 84 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

This branch was previously deployed

1 inactive deployment
Preview — cac6605a Deployed Oct 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant