Observed on Devin CLI 3000.11.3 (9c803229faa4), swe-2-high
A denied MCP call can end a noninteractive turn with exit status 0, no final answer, and an ATIF export ending at the tool request rather than the blocked result. This was reproduced directly with Devin on September 26, independently of the Open Pstack launcher. This is a historical version-specific observation, not a claim about untested newer releases.
Direct reproduction
From an Open Pstack checkout, save the following private config and diagnostic prompt. Keep permission denial in place; no MCP approval or persistent user configuration changes are required by the test.
direct-mcp.config.json:
{
"shell": {
"setup_complete": true
},
"subagents_enabled": false,
"disabled_tools": [
"exec",
"mcp_call_tool",
"mcp_list_tools",
"mcp_list_servers",
"mcp_read_resource"
],
"auto_update": false,
"notify": "never",
"read_config_from": {
"agents_standard": false,
"cursor": false,
"windsurf": false,
"claude": false,
"copilot": false,
"opencode": false,
"zed": false
},
"permissions": {
"deny": [
"mcp__*",
"fetch",
"edit",
"write",
"exec",
"Write(**)"
]
},
"version": 1
}
direct-mcp.prompt:
This is a read-only diagnostic. Do not load skills. If you have an MCP calling tool, use it to call get_issue on server github with owner arjitj2, repo open-pstack, issue_number 48. Do not perform writes. If no MCP calling tool is available, read plugins/pstack/.codex-plugin/plugin.json using the read tool instead. Finish with a final plain text answer saying which source you could inspect and DIAGNOSTIC_COMPLETE. Do not request permission or use exec.
devin --config direct-mcp.config.json --model swe-2-high --permission-mode auto --respect-workspace-trust false --prompt-file direct-mcp.prompt --export direct-mcp.export.json --print < /dev/null
Observed: 8.014 seconds, exit 0, empty stdout/stderr. The ATIF-v1.7 export ends with an agent mcp_call_tool request to the read-only public issue above, with an empty message and no final answer. Scoped inspection of the same local session separately found an approval-denied tool result; the export omitted that blocked observation. A configured GitHub MCP server's existence is not established: approval may precede server lookup.
Controls and boundaries
- Same CLI/private-config mechanism, ordinary
read disabled: no read call, final READ_UNAVAILABLE, exit 0 (8.437 seconds).
- Paired
read enabled: manifest read, final READ_OK, exit 0 (11.879 seconds).
- Separate launcher probes disabling
mcp_call_tool or mcp also selected the denied call and ended incompletely. None of these selectors is a verified workaround.
The controls show the config applies to ordinary tools; they do not establish which MCP selector names are supported. No credentials, reasoning, or raw conversation exports are included in this report.
Expected behavior / questions
- What supported per-invocation setting removes the generic MCP proxy and all MCP access without altering persistent user configuration? Are these names valid
disabled_tools selectors?
- Can a denied tool call be returned to the model so it can finish with a clear final answer? If the turn must terminate, expose an explicit failure/incomplete outcome.
- Why does the process exit 0 with no final response, and why is the blocked observation absent from ATIF?
Related feature request #12 asks for compact structured results. This bug concerns existing print/export behavior and does not depend on implementing that feature. Issue #8 concerns MCP advertisement/registry mismatch; this report instead demonstrates permission-denied termination and missing terminal export evidence. No automatic retry, permission bypass, or relaxed completion checks are requested.
Observed on Devin CLI 3000.11.3 (9c803229faa4), swe-2-high
A denied MCP call can end a noninteractive turn with exit status 0, no final answer, and an ATIF export ending at the tool request rather than the blocked result. This was reproduced directly with Devin on September 26, independently of the Open Pstack launcher. This is a historical version-specific observation, not a claim about untested newer releases.
Direct reproduction
From an Open Pstack checkout, save the following private config and diagnostic prompt. Keep permission denial in place; no MCP approval or persistent user configuration changes are required by the test.
direct-mcp.config.json:{ "shell": { "setup_complete": true }, "subagents_enabled": false, "disabled_tools": [ "exec", "mcp_call_tool", "mcp_list_tools", "mcp_list_servers", "mcp_read_resource" ], "auto_update": false, "notify": "never", "read_config_from": { "agents_standard": false, "cursor": false, "windsurf": false, "claude": false, "copilot": false, "opencode": false, "zed": false }, "permissions": { "deny": [ "mcp__*", "fetch", "edit", "write", "exec", "Write(**)" ] }, "version": 1 }direct-mcp.prompt:Observed: 8.014 seconds, exit 0, empty stdout/stderr. The ATIF-v1.7 export ends with an agent
mcp_call_toolrequest to the read-only public issue above, with an empty message and no final answer. Scoped inspection of the same local session separately found an approval-denied tool result; the export omitted that blocked observation. A configured GitHub MCP server's existence is not established: approval may precede server lookup.Controls and boundaries
readdisabled: no read call, finalREAD_UNAVAILABLE, exit 0 (8.437 seconds).readenabled: manifest read, finalREAD_OK, exit 0 (11.879 seconds).mcp_call_toolormcpalso selected the denied call and ended incompletely. None of these selectors is a verified workaround.The controls show the config applies to ordinary tools; they do not establish which MCP selector names are supported. No credentials, reasoning, or raw conversation exports are included in this report.
Expected behavior / questions
disabled_toolsselectors?Related feature request #12 asks for compact structured results. This bug concerns existing print/export behavior and does not depend on implementing that feature. Issue #8 concerns MCP advertisement/registry mismatch; this report instead demonstrates permission-denied termination and missing terminal export evidence. No automatic retry, permission bypass, or relaxed completion checks are requested.