#Artifact siap copy
@MSO
Terapkan atau upgrade MCP untuk project ini sampai production-grade.
Gunakan canonical MCP Builder Kit sebagai source-of-truth:
- Repo: https://github.com/rahmanef63/connectors
- Ikuti AGENTS.md
- Gunakan skill .agents/skills/mcp-project-builder/SKILL.md
- Gunakan cookbook cn-mcp-core/ dan shared/ hanya sesuai kebutuhan.
- Jangan meng-copy pattern secara buta. Audit arsitektur project ini dahulu, lalu adaptasikan MCP ke existing SSOT/domain/service layer project.
- Jika package @rahmanef63/mcp-builder sudah tersedia di npm, boleh gunakan versi terbarunya. Jika belum, gunakan repo connectors langsung.
- Jangan bergantung pada GitHub Actions. Verification harus dapat dijalankan lokal dan oleh CI/CD provider apa pun, termasuk Batonly.
==================================================
0. TUJUAN
==================================================
Saya ingin project ini memiliki MCP yang:
1. Bisa digunakan dari ChatGPT, Codex, Claude, Cursor, MSO, dan MCP client standar lainnya selama client tersebut mendukung capability yang dipakai.
2. Model/provider agnostic.
3. Tidak membuat business logic kedua khusus MCP.
4. Menggunakan function/domain/service yang sudah ada di project sebagai SSOT.
5. Aman untuk multi-user/multi-tenant.
6. Mempunyai tool/function calling yang benar-benar usable oleh AI, bukan sekadar endpoint yang technically works.
7. Mempunyai auth, scopes, permission, audit, rate limit, validation, error handling, pagination, output contract, dan security yang jelas.
8. Bisa dites secara deterministic.
9. Mempunyai skill/plugin/package bila memang berguna.
10. Bisa di-update tanpa merusak existing consumer/tool contract.
11. Tidak dianggap selesai hanya karena build/test pass. Harus diverifikasi sampai runtime dan MCP client nyata.
Jika MCP sudah ada:
- audit dahulu;
- pertahankan compatibility sebisa mungkin;
- upgrade secara incremental;
- jangan rewrite total kalau existing architecture sudah benar.
Jika MCP belum ada:
- bangun dari nol mengikuti flow di bawah.
==================================================
1. AUDIT CURRENT STATE DULU
==================================================
Sebelum edit apa pun, identifikasi dan catat:
- canonical repo;
- branch dan SHA;
- active worktree/agent lain;
- framework;
- package manager;
- runtime/deployment;
- public domain/origin;
- backend/database;
- auth/session system;
- user/organization/workspace/tenant model;
- RBAC/permission model;
- existing service/domain functions;
- API routes;
- MCP implementation existing bila ada;
- OAuth implementation existing bila ada;
- plugin/skill existing;
- current tests;
- environment/deployment owner;
- secret store;
- audit/logging;
- rate limiting;
- file/storage handling;
- current production state.
Cek active agents/workflows sebelum edit.
Kalau repo shared atau agent lain aktif:
- gunakan isolated worktree;
- jangan overwrite pekerjaan agent lain;
- jangan reset/delete branch atau commit yang bukan milik pekerjaan ini.
Bedakan dengan jelas:
- source repo;
- generated files;
- installed package;
- running runtime/container;
- persistent data;
- cached MCP client toolset.
Jangan memperbaiki source yang salah target.
==================================================
2. AUDIT FUNCTION CALLING / CAPABILITY LAYER
==================================================
Ini bagian penting.
Cari semua function/capability yang sebenarnya sudah ada dalam project.
Audit minimal:
- domain service;
- server actions;
- queries;
- mutations;
- REST/API handlers;
- Convex functions;
- SDK/client abstraction;
- internal commands;
- project functions;
- integration actions.
Buat capability map:
| User outcome | Existing function/handler | MCP primitive | MCP name | Scope | Risk | Approval | Input | Output |
|---|---|---|---|---|---|---|---|---|
Jangan expose function hanya karena function tersebut ada.
Tentukan untuk setiap capability apakah seharusnya menjadi:
- MCP Tool;
- MCP Resource;
- MCP Prompt;
- Agent Skill;
- internal-only function;
- atau tidak boleh diekspos sama sekali.
Gunakan prinsip:
Tool
Untuk operasi yang dipilih/dipanggil model dengan argument berdasarkan konteks percakapan.
Contoh:
projects_list
project_get
invoice_create
post_publish
Resource
Untuk data readable yang punya address/identity stabil.
Contoh:
project://123/spec
company://profile
app://tool-catalog
Prompt / Skill
Untuk workflow berulang yang membutuhkan urutan, policy, recovery, atau reasoning guidance.
Contoh:
deploy-project
prepare-client-report
create-prd
Internal only
Untuk function yang terlalu rendah-level, raw, privileged, implementation detail, atau berbahaya.
Jangan menjadikan semua internal functions sebagai MCP tools.
==================================================
3. FUNCTION CALLING DESIGN
==================================================
Untuk setiap tool/function calling yang dibuat, pastikan:
A. Nama
Gunakan nama stabil, verb-clear, snake_case.
Bagus:
projects_list
projects_get
projects_create
projects_set_status
projects_archive
Hindari:
manage
do_action
execute
update_anything
run_function
Nama MCP adalah public API.
Jangan rename tool existing tanpa:
- compatibility review;
- migration;
- alias/deprecation jika diperlukan;
- client rescan consideration.
B. Description
Tool description harus membantu model menentukan:
1. kapan menggunakan tool;
2. kapan jangan menggunakan tool;
3. prerequisite;
4. defaults;
5. side effect;
6. consequence jika destructive;
7. dari mana ID diperoleh;
8. output apa yang berguna untuk call berikutnya.
Contoh pola:
Use this when ...
Do not use this when ...; use X instead.
project_id must come from projects_list or projects_search.
This permanently publishes the page.
Jangan membuat description hanya seperti:
Create project.
C. Input schema
Setiap public MCP tool harus memiliki schema yang:
- object;
- bounded;
- jelas;
- property description lengkap;
- enum kalau domain terbatas;
- min/max bila relevan;
- required benar;
- additionalProperties: false bila memungkinkan.
Jangan meminta AI mengirim:
- userId;
- tenantId;
- organizationId yang sebenarnya dapat diperoleh dari auth;
- role;
- internal permission;
- credential;
- raw access token.
Identity dan authorization harus berasal dari authenticated server context.
D. Function handler
MCP handler harus tipis.
Ideal:
MCP Tool
→ validate args
→ resolve authenticated principal
→ permission/policy
→ existing service/domain function
→ normalize result
→ redact
→ audit
→ response
Jangan:
MCP Tool
→ implement business logic baru yang berbeda dengan web app.
MCP bukan second backend.
==================================================
4. FIRST-CLASS TOOL VS GENERIC FUNCTION CALLING
==================================================
Jangan membuat satu tool global baru untuk setiap function yang dynamic/installable.
Jika capability adalah core/stable product action:
→ gunakan first-class MCP tool.
Jika function berasal dari:
- dynamically installed integration;
- project-specific plugin;
- downstream MCP;
- project-owned extensibility;
- custom automation;
gunakan pattern generic discovery/call bila lebih cocok.
Contoh:
project_capabilities
→ discover available project capabilities.
project_function_call
→ call one explicitly declared project function.
project_mcp_tools
→ discover downstream MCP tools.
project_mcp_call
→ call exact downstream tool.
Jangan flatten ribuan dynamic downstream tools ke satu stable global catalog karena akan menyebabkan:
- tool explosion;
- collisions;
- context waste;
- client cache instability;
- compatibility issues.
Untuk generic function calling:
- function harus explicitly declared;
- schema harus discoverable;
- allowlist;
- exact function name;
- bounded args;
- project/root isolation;
- scope enforcement;
- permission enforcement;
- audit;
- timeout;
- no secret exposure.
==================================================
5. AUTHENTICATION DAN IDENTITY
==================================================
MCP request harus authenticate sebelum catalog/dispatch.
Identity tidak boleh berasal dari tool arguments.
Flow:
request
→ authenticate credential
→ principal/user
→ tenant/workspace memberships
→ permissions
→ allowed catalog
→ tool validation
→ call-time authz
→ execute
Untuk multi-tenant:
- cek membership setiap request/call;
- jangan hanya cek saat token dibuat;
- jangan percaya client-supplied tenant;
- pastikan object ownership diverifikasi di backend handler juga.
Jika aplikasi sudah punya auth:
reuse existing identity/domain authority bila aman.
Jangan membuat credential store kedua tanpa kebutuhan.
==================================================
6. AUTHORIZATION DAN SCOPES
==================================================
Definisikan minimal authority model.
Contoh sederhana:
read
write
Jika project memang punya host-level execution:
read < write < exec
Jangan menambahkan exec jika produk tidak membutuhkannya.
Tool visibility dan tool execution harus sama-sama enforce scope.
Artinya:
tools/list
→ write tool tidak terlihat oleh read-only principal.
tools/call
→ write tool tetap ditolak bila dipanggil langsung dengan read credential.
Harus ada test untuk keduanya.
Derive scope sejauh mungkin dari satu source-of-truth effect metadata.
Misalnya:
readOnlyHint=true
→ read scope.
Mutation:
→ write scope.
Jangan punya:
- annotation mengatakan read;
- scope mengatakan write;
- approval mengatakan safe;
- handler sebenarnya destructive.
==================================================
7. TOOL ANNOTATIONS
==================================================
Set minimal:
- readOnlyHint
- destructiveHint
- idempotentHint
- openWorldHint
Nilainya harus sesuai behavior nyata.
Contoh:
list data:
- readOnly true
- destructive false
- idempotent true
set exact status:
- readOnly false
- destructive false
- idempotent true
append comment:
- readOnly false
- destructive false
- idempotent false
delete/revoke/send/publish:
- readOnly false
- destructive true
- idempotent sesuai implementasi
Annotation bukan security enforcement.
Backend policy tetap wajib.
==================================================
8. APPROVAL DAN RISK
==================================================
Klasifikasikan tools:
- safe read;
- write;
- sensitive write;
- destructive;
- irreversible;
- external/public side-effect;
- privileged execution.
Untuk destructive/irreversible:
- jelaskan consequence sebelum call;
- approval jika policy mengharuskan;
- bind approval ke exact action + canonical arguments;
- approval single-use;
- perubahan satu argument = approval baru.
Jangan izinkan model mengubah argumen setelah approval.
Refusal harus fail closed.
==================================================
9. MCP RESULTS / OUTPUT CONTRACT
==================================================
Jangan return payload random.
Normalize success ke object envelope.
Contoh:
Get:
{ found, item }
List:
{ items, nextCursor, total }
Write:
{ ok, id, changedFields }
Scalar:
{ result }
Not found:
{ found: false, item: null }
Setiap result yang menggunakan structuredContent harus memiliki outputSchema yang sesuai.
Text dan structured data harus berasal dari normalized payload yang sama agar tidak drift.
Text harus model-friendly.
Structured content harus machine-friendly.
IDs/cursors untuk next call harus tetap tersedia.
==================================================
10. ERROR MODEL
==================================================
Pisahkan:
Protocol/dispatch error
Gunakan JSON-RPC error untuk:
- malformed request;
- unknown method;
- unknown tool;
- invalid params;
- unsupported protocol/version;
- transport mismatch.
Tool execution error
Tool berhasil ditemukan/dipanggil tetapi operasinya gagal:
return normal tool result dengan:
isError: true
dan text yang actionable.
Contoh categories:
- AUTHENTICATION_REQUIRED
- INSUFFICIENT_SCOPE
- APPROVAL_REQUIRED
- POLICY_DENIED
- CONNECTION_MISSING
- DEVICE_OFFLINE
- VALIDATION_ERROR
- NOT_FOUND
- RATE_LIMITED
- TIMEOUT
- UPSTREAM_ERROR
Jangan membuat agent retry semua error.
Skill/instructions harus menjelaskan:
- approval required → stop, tunggu user;
- policy denied → jangan bypass;
- insufficient scope → reconnect/re-authorize;
- device offline → perangkat harus online;
- validation → perbaiki args;
- timeout/upstream → boleh bounded retry.
==================================================
11. PAGINATION, SIZE, TIMEOUT
==================================================
Semua list/search yang berpotensi besar harus bounded.
Input minimal:
- limit
- cursor bila perlu.
Output:
- items
- nextCursor
- hasMore atau total
Jangan silently truncate.
Tetapkan:
- max request bytes;
- max result bytes;
- max list page;
- timeout;
- cancellation;
- rate limits.
Tool rich seperti screenshot/file boleh punya limit terpisah yang eksplisit.
==================================================
12. FILE, IMAGE, URL
==================================================
Jika ada file/image:
Baca dan ikuti shared/file-inputs.md.
Security minimal:
- authorize sebelum fetch;
- HTTPS only untuk remote arbitrary URL jika applicable;
- block private network;
- block localhost/metadata/link-local;
- redirect limit;
- MIME allowlist;
- size limit;
- timeout;
- basename sanitization;
- no absolute local filesystem path di result;
- signed URL harus short-lived;
- storage credential tidak boleh keluar.
Jangan menerima arbitrary URL tanpa SSRF protection.
==================================================
13. OAUTH
==================================================
Kalau MCP hanya local/private developer:
bearer/token phase dapat digunakan bila sesuai.
Kalau akan dipakai consumer hosted clients seperti ChatGPT/Claude:
implement auth berdasarkan current MCP/OAuth specification.
Audit docs terbaru sebelum coding.
Minimal perhatikan:
- protected resource metadata;
- authorization server metadata;
- PKCE S256;
- issuer;
- resource/audience;
- redirect exact-match;
- scopes;
- code TTL;
- single-use auth code;
- token TTL;
- revoke;
- no raw credential at rest;
- token response no-store;
- proper WWW-Authenticate challenge.
Jangan membuat OAuth hanya “formally present”.
Test attack/refusal cases.
==================================================
14. MCP PROTOCOL / TRANSPORT
==================================================
Gunakan official MCP SDK bila memungkinkan.
Remote:
prefer Streamable HTTP/current MCP transport.
Local:
stdio bila cocok.
Jangan membuat business logic berbeda berdasarkan:
ChatGPT
Claude
Cursor
Codex
MSO
Semua harus memakai server capability yang sama.
Host-specific behavior hanya pada:
- registration;
- packaging;
- UI metadata;
- compatibility wrapper.
Jika mendukung lebih dari satu protocol era:
- advertise hanya yang benar-benar implemented;
- test parity;
- shared policy/handler;
- modern/legacy tidak boleh menghasilkan permission yang berbeda.
==================================================
15. SERVER INSTRUCTIONS
==================================================
Tambahkan server-level instructions bila berguna.
Server instructions menjelaskan:
- produk ini apa;
- data siapa yang sedang diakses;
- global conventions;
- ID conventions;
- retry/refusal behavior;
- domain map;
- capabilities yang tidak tersedia.
Tool description menjelaskan satu tool.
Jangan copy seluruh manual ke setiap tool.
==================================================
16. SKILL
==================================================
Buat skill hanya jika ada workflow yang memang tidak cukup dijelaskan oleh tool descriptions.
Skill harus menjelaskan:
- non-obvious sequence;
- stop/retry rules;
- destructive confirmation;
- opaque ID flow;
- recovery;
- project/domain rules.
Skill bukan copy dari semua schema.
Preferred structure:
SKILL.md
agents/openai.yaml
references/
assets/
scripts/ hanya bila deterministic helper diperlukan.
Usahakan SKILL.md compact.
Gunakan progressive disclosure.
==================================================
17. PLUGIN / AGENT PLUGIN PACKAGING
==================================================
Kalau MCP akan didistribusikan sebagai Agent Plugin, gunakan struktur current portable-first.
Audit dokumentasi OpenAI terbaru sebelum final packaging.
Prefer:
plugin.json
mcp.json
skills/
assets/
Compatibility .codex-plugin/plugin.json hanya jika benar-benar diperlukan.
Jangan mechanically rename old .mcp.json menjadi mcp.json karena contract dapat berbeda.
Jangan commit:
- API keys;
- OAuth access token;
- cookies;
- npm token;
- fake registered app IDs.
Registered hosted connection IDs hanya boleh menggunakan ID nyata dari target workspace.
==================================================
18. FUNCTION CALLING TEST SUITE
==================================================
Buat contract tests yang secara otomatis memeriksa SEMUA tools.
Minimal:
Catalog contract
Snapshot atau deterministic hash tools/list.
Perubahan berikut harus terlihat dalam diff:
- tool name;
- title;
- description;
- required args;
- schema;
- annotations;
- scope;
- output schema.
Jangan auto-update snapshot tanpa review.
Tool naming
Assert:
- unique names;
- no flattening collision;
- no reserved/invalid name;
- deterministic order.
Description
Assert:
- non-empty;
- cukup detail;
- destructive tool menjelaskan consequence;
- required opaque IDs menyebut sumber ID dari tool lain.
Input schema
Assert:
- object;
- bounded;
- fields documented;
- no user/tenant identity fields;
- enums valid;
- no unrestricted arbitrary command/path/url tanpa explicit design.
Scope tests
Test:
- read credential hanya melihat read tool;
- read credential tidak dapat call write;
- write sees appropriate catalog;
- destructive cannot be reached through read.
Identity test
Coba inject:
- userId lain;
- tenantId lain;
- organizationId lain.
Pastikan tidak dapat impersonate.
Result fixtures
Test:
- normal item;
- empty list;
- null/not-found;
- pagination;
- write acknowledgement;
- file result;
- error result.
Validate against outputSchema.
Error behavior
Pastikan:
- tool failure → isError;
- protocol failure → JSON-RPC error;
- auth failure → proper challenge;
- retry guidance benar.
==================================================
19. GOLDEN PROMPT / MODEL ROUTING TEST
==================================================
Ini wajib untuk MCP yang punya catalog berarti.
Untuk SETIAP tool buat minimal satu direct prompt.
Tambahkan:
Direct
Prompt jelas meminta tool tersebut.
Indirect
Prompt seperti user normal yang tidak menyebut nama tool.
Follow-up
Tool kedua memakai ID/cursor dari hasil tool pertama.
Negative
Prompt yang seharusnya tidak memanggil tool.
Contoh:
Direct:
“List semua project saya.”
Indirect:
“Apa saja pekerjaan yang sedang aktif sekarang?”
Follow-up:
“Buka project kedua tadi dan tunjukkan detailnya.”
Negative:
“Jelaskan apa itu project management.”
Negative harus expect no call.
Tambahkan conflict tests untuk tool yang mudah tertukar.
==================================================
20. BEHAVIORAL EVALUATION
==================================================
Selain unit test, buat realistic eval.
Minimal beberapa scenario end-to-end yang:
- nyata;
- multi-step;
- expected outcome jelas;
- answer/result diverifikasi independen;
- tidak bergantung pada state random;
- menyertakan model/version/catalog digest saat dijalankan.
Tujuannya:
bukan hanya “tool works”,
tetapi “AI dapat menggunakan tool dengan benar”.
==================================================
21. SECURITY TEST
==================================================
Tambahkan attack/refusal tests sesuai surface:
- auth bypass;
- tenant impersonation;
- read → write escalation;
- revoked token;
- expired token;
- wrong audience;
- wrong issuer;
- replay;
- OAuth code reuse;
- redirect manipulation;
- PKCE downgrade;
- input overflow;
- oversized body;
- SSRF;
- path traversal;
- command injection;
- tool collision;
- approval replay;
- changed-arguments-after-approval;
- rate-limit;
- secret leakage;
- absolute filesystem path leakage.
==================================================
22. OPERATIONAL SAFETY
==================================================
Untuk remote write-enabled MCP, implement atau pertahankan:
- deployment kill switch;
- max-scope ceiling;
- catalog version/hash;
- immediate revocation;
- write rate limit;
- destructive rate limit;
- timeout metrics;
- error metrics;
- audit persistence;
- safe redaction.
Jika supervised runtime/local processes ada:
- slot health;
- stale process detection;
- restart limit;
- restart-storm suppression;
- resource cleanup.
Jangan loop restart tanpa batas.
==================================================
23. AUDIT LOGGING
==================================================
Audit mutation/sensitive calls.
Record:
- actor/principal;
- tool/action;
- target;
- outcome;
- timing;
- policy/approval state;
- request correlation.
Jangan record:
- raw token;
- cookies;
- passwords;
- entire file body;
- entire user message;
- sensitive arguments tanpa redaction.
Jika audit durability adalah security requirement:
fail closed atau tandai sebagai control-plane incident sesuai architecture.
==================================================
24. VERSIONING
==================================================
Treat public MCP contract sebagai API.
Maintain:
- server version;
- toolset version;
- toolset hash/digest;
- plugin/package version;
- catalog version bila perlu.
Jika descriptor berubah:
- bump appropriate version;
- run contract diff;
- refresh external MCP clients;
- rescan tools;
- start fresh conversation/session untuk testing.
Jangan menganggap client otomatis melihat schema terbaru.
==================================================
25. LOCAL VERIFICATION
==================================================
Sebelum deploy jalankan seluruh applicable gate:
- format/lint;
- typecheck;
- unit tests;
- MCP contract tests;
- scope tests;
- auth tests;
- OAuth tests;
- policy tests;
- file security tests;
- golden prompt structural tests;
- behavioral eval jika tersedia;
- package/plugin checks;
- secret scan;
- dependency/security audit;
- production build.
Jangan hanya test happy path.
==================================================
26. WIRE TEST
==================================================
Gunakan official MCP Inspector/SDK/client jika memungkinkan.
Jangan menjadikan homemade mock client sebagai satu-satunya proof.
Test:
- initialize/discover sesuai supported protocol;
- tools/list;
- tools/call;
- resources jika ada;
- prompts jika ada;
- OAuth discovery;
- unauthenticated challenge;
- authenticated flow;
- pagination;
- error behavior.
==================================================
27. DEPLOYMENT
==================================================
Deploy hanya setelah local contract green.
Setelah deploy, verify actual runtime:
- exact deployed SHA/version;
- health;
- correct domain;
- HTTPS;
- /mcp;
- discovery URLs;
- auth;
- token;
- catalog;
- toolset hash;
- logs;
- no unexpected redirects/proxy stripping.
Jangan claim deployed dari build output saja.
==================================================
28. LIVE ACCEPTANCE
==================================================
Lakukan real deployed tests:
1. unauthenticated MCP request;
2. OAuth/auth flow;
3. authenticated tools/list;
4. one real read;
5. one real write jika applicable;
6. approval-gated write jika applicable;
7. insufficient scope;
8. revocation;
9. pagination;
10. error/refusal behavior;
11. file flow bila ada;
12. external MCP client rescan;
13. fresh client session;
14. actual function call through ChatGPT/Claude/Cursor/MSO yang menjadi target.
Pastikan result benar di underlying application/database juga.
==================================================
29. FUNCTION CALLING DOD
==================================================
Function calling dianggap benar hanya jika:
- AI memilih tool yang tepat;
- AI tidak memanggil tool pada negative cases;
- opaque IDs diperoleh dari tool yang benar;
- follow-up bisa memakai result sebelumnya;
- validation menolak malformed args;
- user/tenant tidak dapat dipalsukan;
- read tidak dapat escalate ke write;
- destructive effect jelas;
- approval tidak dapat direplay;
- handler memakai existing business SSOT;
- errors actionable;
- outputs bounded;
- client bisa memakai result untuk next action.
==================================================
30. MCP REGISTRY
==================================================
Jangan otomatis publish ke MCP Registry.
Tentukan dulu:
Apakah artifact ini benar-benar sebuah MCP server?
Jika hanya:
- Agent Skill;
- scaffolder;
- CLI;
- MCP builder;
npm/package distribution cukup.
Jika benar-benar mendistribusikan MCP server dan ingin discoverable melalui official MCP Registry:
- audit current official Registry docs;
- publish artifact ke package registry lebih dulu;
- tambahkan package ownership metadata seperti mcpName jika current npm MCP Registry contract memerlukannya;
- generate/validate server.json;
- gunakan official mcp-publisher;
- authenticate namespace;
- publish metadata;
- verify registry entry/version/package parity.
MCP Registry adalah metadata registry, bukan replacement npm.
==================================================
31. DOCUMENTATION
==================================================
Update durable docs.
Minimal dokumentasikan:
- what MCP exposes;
- public endpoint;
- auth model;
- scopes;
- tool groups;
- permission boundary;
- what MCP explicitly cannot do;
- install/connect instructions;
- client refresh instructions;
- security model;
- test commands;
- deploy/runbook;
- versioning;
- package/plugin info;
- troubleshooting;
- rollback.
Jangan simpan credentials di docs.
==================================================
32. BATONLY
==================================================
Update Batonly project selama pekerjaan.
Record:
- planning;
- remaining tasks;
- implementation progress;
- MCP public contract;
- tests;
- security checks;
- deployment evidence;
- live verification;
- blockers;
- DOD;
- handoff.
Jangan mark completed hanya karena source selesai.
Batonly harus bisa menjawab:
- tested?
- merged?
- deployed?
- verified live?
- client MCP tested?
- security checked?
secara terpisah.
==================================================
33. MERGE / BRANCH / CLEANUP
==================================================
Setelah semua verified:
- inspect diff;
- ensure no unrelated changes;
- cleanup generated/unused files;
- run secret scan;
- commit;
- push;
- PR bila workflow project menggunakan PR;
- merge secara safe;
- verify main SHA;
- rebuild/redeploy jika diperlukan;
- verify production exact SHA;
- cleanup hanya branch/worktree yang memang dibuat oleh pekerjaan ini.
Jangan delete branch agent lain.
==================================================
34. HARD CONSTRAINTS
==================================================
Jangan:
- membuat MCP backend terpisah dari business SSOT tanpa alasan;
- expose raw shell/filesystem/network secara default;
- menyimpan secret di args/tool result/log;
- menerima userId dari model sebagai identity authority;
- membuat host-specific business logic;
- membuat write tool terlihat sebagai read;
- menganggap annotation sebagai security enforcement;
- silently truncate result;
- membuat arbitrary generic execute tool;
- mengklaim OAuth selesai hanya karena discovery JSON ada;
- mengklaim MCP selesai hanya karena curl /health sukses;
- mengklaim production-ready tanpa live MCP call;
- menurunkan existing security;
- mematikan existing feature agar tests hijau;
- membuat duplicate implementation ketika existing guarded function dapat dipakai;
- menambahkan GitHub Actions sebagai requirement jika project memakai CI/CD provider lain.
==================================================
35. DEFINITION OF DONE
==================================================
Pekerjaan baru boleh disebut selesai jika:
- current architecture telah diaudit;
- function/capability map dibuat;
- correct MCP primitive dipilih;
- tool naming/descriptions/schema benar;
- function calling benar-benar reusable;
- identity server-derived;
- scopes enforce list + call;
- backend ownership/RBAC rechecked;
- results/outputSchema valid;
- pagination/limits/timeouts ada;
- approval/policy sesuai risk;
- audit/redaction ada;
- OAuth/auth sesuai target clients;
- MCP protocol test pass;
- golden prompt tests pass;
- behavioral eval pass bila applicable;
- security/attack tests pass;
- dependency audit reviewed;
- production build pass;
- deployed runtime verified;
- real MCP client can connect;
- real read call works;
- real write/approval call works bila supported;
- revocation/insufficient scope works;
- tool rescan/fresh session verified;
- underlying application state matches expected result;
- docs/runbook updated;
- Batonly updated;
- main/release SHA known;
- no secrets leaked;
- rollback documented.
==================================================
36. FINAL REPORT FORMAT
==================================================
Saat selesai, jangan hanya bilang “done”.
Laporkan:
Architecture
Apa yang dipakai sebagai MCP SSOT dan kenapa.
Function Calling
- jumlah tools;
- resources;
- prompts/skills;
- dynamic functions/integrations;
- scope model;
- approval model.
Reused Existing Functions
Function/service/domain handlers apa saja yang dipakai ulang.
New MCP Components
Apa saja yang benar-benar baru.
Security
Auth, OAuth, scope, tenant isolation, rate limits, redaction, audit, file security.
Tests
Command dan hasil:
- unit;
- contract;
- function calling;
- golden prompts;
- eval;
- security;
- OAuth;
- build.
Runtime
- deployed version;
- SHA;
- domain;
- MCP endpoint;
- health.
Live Acceptance
Jelaskan actual calls yang dilakukan dan hasilnya.
Client Compatibility
Status:
- ChatGPT;
- Codex;
- Claude;
- Cursor;
- MSO;
- lainnya jika dites.
Gunakan status:
- VERIFIED
- NOT TESTED
- BLOCKED
Jangan infer.
Remaining Risks
Apa yang benar-benar belum dibuktikan.
Git
- branch;
- commit;
- PR;
- main SHA;
- cleanup status.
Batonly
Task/status/evidence yang sudah di-update.
Kerjakan sampai sejauh mungkin tanpa berhenti hanya untuk meminta konfirmasi teknis yang bisa kamu audit sendiri. Jika ada hal yang benar-benar membutuhkan user presence—misalnya login, consent, 2FA, approval destructive, atau ownership eksternal—selesaikan semua pekerjaan lain terlebih dahulu lalu berikan satu quick action yang sangat spesifik.
Sumber pembelajaran: 9. Master Prompt — Build / Upgrade Production MCP. Resource ini menyimpan artifact reusable; penjelasan konsep tetap di Classroom.