Skip to content

Feat/mcp eval phases - #102

Open
operetz-rh wants to merge 9 commits into
mcp-evaluation-pipelinefrom
feat/mcp-eval-phases
Open

operetz-rh wants to merge 9 commits into
mcp-evaluation-pipelinefrom
feat/mcp-eval-phases

Conversation

@operetz-rh

Copy link
Copy Markdown

Summary

Adds MCP-server evaluation Phase 1 (static / build-time) and Phase 2 (deterministic conformance) per the ADR (Approach 4), scoped to those two phases only — Phase 3 (behavioral) and pipeline orchestration are out of scope here. Targeted at the mcp-evaluation-pipeline branch so all MCP pipeline pieces land together before the combined PR to main.

Changes

  • Phase 1 static scanners + gates (abevalflow/mcp/phase1, scripts/mcp): secrets (gitleaks), no-user-code (semgrep, offline ruleset for Python/JS/TS/Go/Java), and license (licensee). Weighted 0–1 scoring with block / warn / disabled modes; a missing scan fails in block mode.
  • Phase 2 deterministic conformance (abevalflow/mcp/phase2, scripts/mcp): black-box probe of a running server over Streamable HTTP (JSON-RPC 2.0), 10 checks, three-state model (pass / fail / not_evaluated — unreachable or undecidable never fails). No LLM. Two checks are consumed from existing Compass facts rather than re-probed.
  • Tekton tasks under pipeline/tasks/konflux/: mcp-phase1-static and mcp-phase2-conformance, following this branch's convention (name == filename, app.kubernetes.io labels).
  • Tests: unit + integration tests for both phases.
  • Coverage: the no-user-code scan surfaces a coverage block so a zero-finding pass shows what was actually scanned.

Test plan

Related

APPENG-6254

operetz-rh and others added 6 commits September 30, 2026 13:39
- Move mcp-phase{1,2} tasks to pipeline/tasks/konflux/, rename to
  mcp-phase1-static / mcp-phase2-conformance, and adopt the app.kubernetes.io
  labels used on the deploy-pipeline branch (name == filename, no namespace).
- Trim redundant/duplicated comments in the Phase 1/2 scanners and gates;
  keep only the WHY notes. No logic change.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@operetz-rh operetz-rh self-assigned this Oct 1, 2026

@IlonaShishov IlonaShishov left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great work @operetz-rh!
Please consider my suggestions bellow

echo "Pipeline repo already cloned, skipping"
exit 0
fi
git clone --depth 1 --branch "$(params.pipeline-repo-revision)" \

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Use Pre-built Container Image Instead of Runtime Git Clone
The current approach has the following issues:

  1. Performance: Each task clones the repo (30-60s) and installs tools (2+ min) on every run
  2. Anti-pattern: Dependencies should be baked into images at build time, not installed at runtime
  3. Inefficiency: Container images are pulled once per pipeline and cached on the node; git clones happen per step and can't be cached
  4. Version drift: pipeline-repo-revision: main means task bundle v0.1 could run different code on different days
  5. Inconsistent: We're not using Tekton's official git-clone task; we're doing ad-hoc bash cloning

For a cleaner approach, you could build a dedicated MCP eval image and use it as the tasks base image:


FROM registry.access.redhat.com/ubi9/python-311:9.6

# Copy ONLY what MCP needs
COPY abevalflow/mcp /opt/abevalflow/mcp
COPY abevalflow/gates /opt/abevalflow/gates
COPY abevalflow/schemas.py /opt/abevalflow/schemas.py
COPY abevalflow/observability /opt/abevalflow/observability
COPY scripts/mcp /opt/scripts/mcp

ENV PYTHONPATH=/opt

# Install tools + minimal Python deps
RUN curl ... | tar -xz gitleaks && \
    pip install semgrep pydantic pyyaml && \
    dnf install ruby && gem install licensee

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ones you fix this, this step and params pipeline-repo-url and pipeline-repo-revision can be removed

REPORTS_DIR="$(workspaces.source.path)/reports/$(params.submission-name)"
mkdir -p "$REPORTS_DIR"

echo "=== Installing gitleaks (secrets) ==="

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tools can be Pre-installed into Pre-built Container Image the become available when used as base image

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Moving the installation to image build stage during dev - eliminates installation errors at runtime that can redundantly fail the pipeline and are irrelevant to the MCP evaluation itself.

results:
- name: phase1-passed
description: Whether all Phase 1 gates passed (true/false).
- name: secrets-passed

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why does the output include a result for each individual check? do they have a purpose in the next tasks?
If not report-path and phase1-passed is enough.

results:
- name: phase2-passed
description: Whether Phase 2 passed (no check FAILED in block mode).
- name: not-evaluated-count

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this a redundant output?

@IlonaShishov

Copy link
Copy Markdown

Another review item:
The split between scripts/mcp/ and abevalflow/mcp/ has a reasonable intent (execution/I/O vs pure evaluation logic) but it's not self-documenting and one must really understand the code for this to make sense. Within scripts/mcp/ there are scanners, probes, evaluators, and utilities and they are all mixed with inconsistent naming - you can't tell which files are Tekton entry points vs internal helpers. Please make the separation clearer through naming and file structure.

operetz-rh and others added 2 commits October 6, 2026 14:29
…arer layout

- Add containers/mcp-eval/Containerfile baking scanners (gitleaks, semgrep,
  licensee) + deps; both Phase 1/2 tasks use it and drop the runtime git clone,
  tool installs, and pipeline-repo-url/revision params
- Trim unused Tekton results (per-gate passes, not-evaluated-count); keep
  phase1/phase2-passed + report-path
- Rename mcp_client.py -> _mcp_client.py and document entry points vs helpers
- compass_fetch: degrade missing/malformed facts to not_evaluated instead of
  aborting Phase 2; pin image Python deps

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants