Problem
Raised by Copilot on the v2.9.0 milestone-merge PR (#2536) and reproduced there.
loadServerFromConfig in core/mcp/node/config.ts (lines 184-190) checks and returns config.mcpServers[serverName] with a bare dynamic lookup. A server name that matches an inherited Object.prototype member (constructor, toString, …) finds the inherited function instead of reporting "not found", and the CLI then fails with an unrelated error:
$ mcp-inspector --cli --config servers.json --server constructor --method tools/list
{"error":{"code":"error","message":"Cannot use 'in' operator to search for 'type' in undefined"}}
$ mcp-inspector --cli --config servers.json --server nope --method tools/list
{"error":{"code":"error","message":"Server 'nope' not found. Available servers: real"}}
store-id.ts deliberately keeps these names valid as store ids (8d83c83), which is only safe while every dynamic read over a user-keyed map is an own-property lookup. This one is not.
Not a regression: 2.8.0 prints the same error.
Expected
An absent server named constructor (or any other inherited name) reports Server 'constructor' not found, like any other absent name. Use Object.hasOwn(config.mcpServers, serverName) here, and check the remaining bare reads over user-keyed maps.
Problem
Raised by Copilot on the v2.9.0 milestone-merge PR (#2536) and reproduced there.
loadServerFromConfigincore/mcp/node/config.ts(lines 184-190) checks and returnsconfig.mcpServers[serverName]with a bare dynamic lookup. A server name that matches an inheritedObject.prototypemember (constructor,toString, …) finds the inherited function instead of reporting "not found", and the CLI then fails with an unrelated error:store-id.tsdeliberately keeps these names valid as store ids (8d83c83), which is only safe while every dynamic read over a user-keyed map is an own-property lookup. This one is not.Not a regression: 2.8.0 prints the same error.
Expected
An absent server named
constructor(or any other inherited name) reportsServer 'constructor' not found, like any other absent name. UseObject.hasOwn(config.mcpServers, serverName)here, and check the remaining bare reads over user-keyed maps.