diff --git a/docs/superpowers/plans/2026-09-18-mcp-interceptors-research-note.md b/docs/superpowers/plans/2026-09-18-mcp-interceptors-research-note.md new file mode 100644 index 0000000..7eaa17d --- /dev/null +++ b/docs/superpowers/plans/2026-09-18-mcp-interceptors-research-note.md @@ -0,0 +1,27 @@ +# MCP Interceptors Research Note Implementation Plan + +> **For agentic workers:** Execute this plan inline with validation checkpoints. + +**Goal:** Add and publish a sourced research note on MCP Interceptors as reusable policy and context mediation. + +**Architecture:** Explain validator/mutator primitives, lifecycle hooks, trust-boundary execution, chain ordering, audit mode, and in-process/sidecar/remote deployment. Map them to CF gateways, proxies, authorization, redaction, validation, and audit. + +**Tech Stack:** Markdown, YAML frontmatter, Devbox, Git, GitHub CLI. + +--- + +### Task 1: Write `research/mcp-interceptors.md` + +- [ ] Add frontmatter with title `MCP Interceptors: Reusable Policy and Context Mediation`, author `Ruben Koster (@rkoster)`, date `2026-09-18`, tags `[authorization, observability-governance, inter-agent-comms, ecosystem-survey]`, `cf_areas: [uaa, capi, diego, loggregator]`, `status: draft`, ratings, and charter/repository/SEP sources. +- [ ] Explain the M x N problem caused by bespoke sidecars, proxies, and gateways for cross-cutting agent concerns. +- [ ] Cover validator and mutator types, lifecycle hooks for tool calls, resource reads, prompts, sampling, elicitation, and extension to LLM/custom workflows. +- [ ] Cover trust-boundary-aware execution, priority-ordered chains, audit mode, and in-process/sidecar/remote deployment trade-offs. +- [ ] Identify sample use cases such as PII redaction, schema validation, and audit logging, and distinguish the experimental proposal from a finalized MCP standard. +- [ ] Assess CF relevance for gateways, sidecars, service proxies, UAA/policy, Loggregator, multi-tenant ordering, and platform/application ownership. +- [ ] Add open questions about ordering, failure behavior, mutation accountability, trust, latency, sensitive data, and interceptor discovery. + +### Task 2: Validate and publish + +- [ ] Run `devbox run validate`, `devbox run test`, and `git diff --check`. +- [ ] Stage only the note and approved spec/plan, commit `docs: add MCP Interceptors research note`, push `research/mcp-interceptors`, and open a checklist-complete PR targeting `main`. +- [ ] Verify PR metadata and CI with `gh pr view`. diff --git a/docs/superpowers/specs/2026-09-18-mcp-interceptors-research-note-design.md b/docs/superpowers/specs/2026-09-18-mcp-interceptors-research-note-design.md new file mode 100644 index 0000000..a664bf8 --- /dev/null +++ b/docs/superpowers/specs/2026-09-18-mcp-interceptors-research-note-design.md @@ -0,0 +1,29 @@ +# MCP Interceptors Research Note Design + +## Goal + +Add a sourced research note on the MCP Interceptors Working Group's proposal for reusable +policy and context mediation across agentic operations. + +## Scope + +The note will cover validator and mutator interceptor types, lifecycle hooks for tools, +resources, prompts, sampling, and elicitation, extensibility to LLM/custom workflows, +trust-boundary-aware execution, priority chains, audit mode, and in-process/sidecar/remote +deployment. It will identify the working group's draft/experimental maturity. + +The Cloud Foundry analysis will map interceptors to gateways, sidecars, authorization, PII +redaction, schema validation, audit logging, service proxies, and Loggregator. It will not claim +existing CF/MCP Interceptors integration. + +## Structure and evidence + +Create `research/mcp-interceptors.md` with the required four sections and frontmatter. Use the +official charter, experimental extension repository, SEP references, and MCP lifecycle context. +Clearly distinguish protocol-level interceptor interfaces from host-specific hooks and general +middleware. + +## Validation + +Run Devbox validation and tests, inspect whitespace/staged files, commit the note and plan on +`research/mcp-interceptors`, push, and open a PR targeting `main` without unrelated artifacts. diff --git a/generated/research-map.html b/generated/research-map.html index 75016a8..0aacdfd 100644 --- a/generated/research-map.html +++ b/generated/research-map.html @@ -23,9 +23,6 @@

Focus use cases

Attested Workload Authority and Mediated Tool AccessExchange platform-attested workload identity for scoped authority while credentials and outbound tool access remain mediated by the platform.Strategic decision: Decide whether CF should become the portable trust and policy layer between agent workloads and the tools they invoke.
Gap, experiments, and evidence
Current CF gap
CF issues workload identity certificates but does not exchange them for scoped tool authority, keep third-party credentials out of workloads, mediate off-platform access, or record delegation-aware audit events.
Candidate POC
Exchange a Diego instance identity certificate for a short-lived scoped token, invoke one allowed tool through a credential proxy and egress mediator, deny another, and emit attributable audit events.
Candidate RFC scope
Define workload token exchange, authority and delegation claims, credential brokering, outbound mediation and policy enforcement, audit events, revocation, and integration boundaries for UAA, routing, and service brokers.
-
Gap, experiments, and evidence
Current CF gap
CF can stage apps and run ephemeral tasks but cannot cheaply compose a reusable environment with per-session workspace state, select stronger isolation, constrain session networking, or resume the session lifecycle.
Candidate POC
Start two isolated sessions from one content-addressed staged environment, attach separate mutable workspaces, apply per-session egress policy, stop one session, and resume it on fresh compute.
Candidate RFC scope
Define environment and workspace references, session identity and lifecycle, isolation classes, network policy, workspace persistence and cleanup, scheduling, quotas, and compatibility with existing CF staging and task APIs.

ResearchIdea

Platform Impact x Maturity

Emerging < Maturity > EstablishedLocal concern < Platform Impact > Platform-wide concern
Unplaced notes (0)
-
-