You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit ad1f32b
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: docs/src/content/docs/reference/tools.md
+12-37Lines changed: 12 additions & 37 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -40,34 +40,28 @@ See **[GitHub Tools Reference](/gh-aw/reference/github-tools/)** for complete co
40
40
41
41
### Linear Tools (`linear:`)
42
42
43
-
Connect to [Linear's official hosted MCP server](https://linear.app/docs/mcp) using the well-known `LINEAR_API_KEY` GitHub Actions secret:
43
+
Connect to [Linear's official hosted MCP server](https://linear.app/docs/mcp) with the `LINEAR_API_KEY` GitHub Actions secret:
44
44
45
45
```yaml wrap
46
46
tools:
47
47
linear: {}
48
48
```
49
49
50
-
Set `token` to use a different secret containing a Linear API key or OAuth access token. The integration uses Streamable HTTP through the MCP gateway and always uses Linear's server-enforced read-only endpoint. Use `allowed` to restrict tool names and `required: false` to make Linear connectivity best-effort:
50
+
Set `token` to use a different secret, `toolsets` to enable groups such as `issues` and `projects`, `allowed` to further restrict tool names, and `required: false` to make connectivity best-effort:
51
51
52
52
```yaml wrap
53
53
tools:
54
54
linear:
55
55
token: ${{ secrets.CUSTOM_LINEAR_TOKEN }}
56
+
toolsets: [issues, projects]
56
57
allowed: ["*"]
57
58
required: true
58
59
```
59
60
60
-
Use `toolsets` to enable related groups of tools without maintaining individual tool names:
61
-
62
-
```yaml wrap
63
-
tools:
64
-
linear:
65
-
toolsets: [issues, projects]
66
-
```
61
+
Supported toolsets are `all`, `attachments`, `comments`, `customers`, `cycles`, `diffs`, `documentation`, `documents`, `initiatives`, `issues`, `milestones`, `projects`, `status_updates`, `teams`, and `users`. The compiler expands toolsets into the gateway's allowed-tool list, and any `allowed` names or wildcards must match a tool in the selected toolsets.
67
62
68
-
Supported toolsets are `all`, `attachments`, `comments`, `customers`, `cycles`, `diffs`, `documentation`, `documents`, `initiatives`, `issues`, `milestones`, `projects`, `status_updates`, `teams`, and `users`. The compiler expands toolsets into the gateway's allowed-tool list. If `allowed` is also set, each name or wildcard must match a tool in the selected toolsets.
63
+
Linear always uses Linear's server-enforced read-only endpoint. The credential is passed to the gateway as an environment variable and sent as an `Authorization: Bearer` header, not embedded in MCP configuration. Like other remote MCP servers, Linear also works with `tools.cli-proxy: true`.
69
64
70
-
The Linear credential is passed to the gateway as an environment variable and sent as an `Authorization: Bearer` header. It is not embedded in MCP configuration. Linear works with `tools.cli-proxy: true` like other remote MCP servers.
71
65
### Jira Tools (`jira:`)
72
66
73
67
Connect to Atlassian's official remote Rovo MCP endpoint from non-interactive GitHub Actions workloads. Browser OAuth, device login, and user-consent flows are not supported.
@@ -99,19 +93,9 @@ tools:
99
93
- searchJiraIssuesUsingJql
100
94
```
101
95
102
-
The `allowed` list is required and accepts only these read-only Jira tools:
103
-
104
-
- `getIssueLinkTypes`
105
-
- `getJiraIssue`
106
-
- `getJiraIssueRemoteIssueLinks`
107
-
- `getJiraIssueTypeMetaWithFields`
108
-
- `getJiraProjectIssueTypesMetadata`
109
-
- `getTransitionsForJiraIssue`
110
-
- `getVisibleJiraProjects`
111
-
- `lookupJiraAccountId`
112
-
- `searchJiraIssuesUsingJql`
96
+
The `allowed` list is required and accepts only these read-only Jira tools: `getIssueLinkTypes`, `getJiraIssue`, `getJiraIssueRemoteIssueLinks`, `getJiraIssueTypeMetaWithFields`, `getJiraProjectIssueTypesMetadata`, `getTransitionsForJiraIssue`, `getVisibleJiraProjects`, `lookupJiraAccountId`, and `searchJiraIssuesUsingJql`.
113
97
114
-
`allowed: ["*"]` is also accepted as shorthand for enabling all nine tools above; it is expanded to that fixed list at compile time and never grants access to the full, unrestricted MCP tool set. Omitting `allowed` or naming a write-capable tool is rejected.
98
+
`allowed: ["*"]` is shorthand for enabling that fixed list at compile time; it never grants access to the full, unrestricted MCP tool set. Omitting `allowed` or naming a write-capable tool is rejected.
115
99
116
100
The endpoint defaults to `https://mcp.atlassian.com/v1/mcp`. Set `url` only when your organization uses another HTTPS Atlassian MCP endpoint. Credentials must be direct GitHub Actions secret expressions; service account keys use the HTTP bearer scheme while API tokens use HTTP Basic authentication generated at runtime.
117
101
@@ -214,29 +198,25 @@ See [GH-AW as an MCP Server](/gh-aw/reference/gh-aw-as-mcp-server/) for availabl
214
198
215
199
### MCP CLI Mounting (`cli-proxy:`)
216
200
217
-
Set `tools.cli-proxy: true` to mount each user-facing MCP server as a standalone CLI tool on `PATH`. When enabled, the agent can invoke MCP servers as shell commands rather than through the MCP protocol:
201
+
Set `tools.cli-proxy: true` to mount each user-facing MCP server as a standalone CLI tool on `PATH`, so the agent can invoke it from shell instead of through the MCP protocol:
218
202
219
203
```yaml wrap
220
204
tools:
221
205
cli-proxy: true
222
206
```
223
207
224
-
With CLI mounting enabled, MCP servers accessible to the workflow (such as `safeoutputs` and `mcpscripts`) are wrapped as executable commands. For example:
208
+
With CLI mounting enabled, workflow-accessible servers such as `safeoutputs` and `mcpscripts` are wrapped as executables:
mcpscripts mcpscripts-gh --args "issue list --limit 5"
229
213
```
230
214
231
-
The safe-output `add_comment` tool uses `--item_number` (not `--issue_number`) to target the issue or pull request — passing `--issue_number` is silently stripped by schema validation.
232
-
233
-
The MCP gateway configuration is unchanged — servers still start as normal. Only the agent's view changes: servers registered for CLI mounting are removed from the MCP tool list and accessed via shell instead.
234
-
235
-
This reduces token consumption from large MCP tool schemas and can simplify workflow prompts when shell-style invocation is preferred.
215
+
For `add_comment`, use `--item_number` rather than `--issue_number`; schema validation strips the latter. CLI mounting changes only the agent-facing interface: the MCP gateway still starts normally, but mounted servers are removed from the MCP tool list and accessed via shell. This can reduce token use from large tool schemas and simplify prompts when shell-style invocation is preferred.
236
216
237
217
Defaults to `false`.
238
218
239
-
CLI mounting requires shell access:the wrappers are ordinary executables invoked from bash. GitHub `gh-proxy` mode is also shell-backed because GitHub reads are performed with the `gh` CLI. When `tools.bash` is disabled (`bash: false` or `bash: []`), `cli-proxy: true` and `tools.github.mode: gh-proxy` are rejected at compile time, and strict mode requires `cli-proxy: false` to be stated explicitly:
219
+
CLI mounting requires shell access because the wrappers are ordinary executables invoked from bash. GitHub `gh-proxy` mode is also shell-backed because GitHub reads are performed with the `gh` CLI. When `tools.bash` is disabled (`bash: false` or `bash: []`), `cli-proxy: true` and `tools.github.mode: gh-proxy` are rejected at compile time, and strict mode requires `cli-proxy: false` to be stated explicitly:
240
220
241
221
```yaml wrap
242
222
tools:
@@ -323,9 +303,4 @@ mcp-servers:
323
303
324
304
## Learn More
325
305
326
-
- [GitHub Tools](/gh-aw/reference/github-tools/) - GitHub API operations, toolsets, and modes
327
-
- [Playwright](/gh-aw/reference/playwright/) - Browser automation and testing configuration
328
-
- [Cache Memory](/gh-aw/reference/cache-memory/) - Persistent memory across workflow runs
- [MCP Scripts](/gh-aw/reference/mcp-scripts/) - Define custom inline tools with JavaScript or shell scripts
331
-
- [MCPs](/gh-aw/guides/mcps/) - Complete Model Context Protocol setup and usage
306
+
See [GitHub Tools](/gh-aw/reference/github-tools/) for GitHub API operations, toolsets, and modes; [Playwright](/gh-aw/reference/playwright/) for browser automation; [Cache Memory](/gh-aw/reference/cache-memory/) and [Repo Memory](/gh-aw/reference/repo-memory/) for persistent context; [MCP Scripts](/gh-aw/reference/mcp-scripts/) for custom inline tools; and [MCPs](/gh-aw/guides/mcps/) for end-to-end Model Context Protocol setup.
0 commit comments