rdmbair15m5-changelog-20260830-1656-mcp-fleet-disable
rdmbair15m5-changelog-20260830-1656-mcp-fleet-disable
Disabled the owner-approved unused external MCP set without uninstalling servers or changing credentials, reducing active tool sprawl while retaining a complete rollback.
Scope
- Fleet scope:
rdmbair15m5,rdmsm4x,rdmbair13m5,rdmpw3265m,rdmpw3275m, andjdmbair13m5. - This record covers changes executed on
rdmbair15m5, the rollback transformer distributed to all six hosts, and the shared operating-project milestone. - Mode: Production; canary first, then five-host expansion.
Files changed on this host
/Users/richh/.codex/config.toml— disabledchrome-devtools,firecrawl,github, andstitch./Users/richh/.claude.json— retained the registrations and disabledchrome-devtoolsandstitchfor every recorded project./Users/richh/Library/Application Support/Claude/claude_desktop_config.json— movedstitchintact from activemcpServerstodisabledMcpServers./Users/richh/.gemini/config/mcp_config.json— disabled the approved 14-server external set registered on this host./Users/richh/scripts/apply_mcp_disable_v1.0.py— installed the rollback-capable host-local transformer, mode 700./Users/richh/Library/Mobile Documents/com~apple~CloudDocs/Codex/projects/AGENTS.md principles/PROJECTS.md— recorded the verified fleet milestone.
No plugin, skill, package, cache, credential, OAuth record, cookie, authentication database, native agent history, private key, security principal, local/project MCP, or provider-bundled runtime was removed or copied.
Commands and method
- Ran live six-host Codex, Claude, Claude Desktop, and agy configuration inventory plus sanitized 45-day invocation-name evidence.
- Published fleet dependency and scope-update messages
20260830-164116-A62F4045and20260830-164837-FC3DD6DA. - Ran
/usr/bin/python3 /Users/richh/scripts/apply_mcp_disable_v1.0.py --apply --stamp 20260830-1648 --expected-host rdmbair15m5after a clean dry-run. - Verified with native
codex mcp list --json,claude mcp list, andagy mcp list, then reparsed active/disabled Claude Desktop maps and backup manifests. - Ran an idempotence dry-run; it reported
changed_files=0.
Verification
- Codex: all four owner-approved targets report
enabled=false;computer-history,node_repl,rdworkbench,replicantdb,tyrell, andmem0-sharedremain enabled. - Claude Code:
chrome-devtoolsandstitchreport disabled for the project; Tyrell, replicantDB, and Mem0 connect, while the pre-existing rdworkbench connection failure remains unrelated. - agy: every target registered on this host reports
disabled;mem0-sharedremains enabled. - Claude Desktop on-disk active target count is zero;
stitchis retained in the disabled registry. - All backup hashes reproduce their manifest
sha256_before; no preservation regression was observed.
Backup and undo
- Private host-local backup:
/Users/richh/Library/Application Support/MCPFleetDisable/backups/20260830-1648/. - Manifest:
/Users/richh/Library/Application Support/MCPFleetDisable/backups/20260830-1648/manifest.json(mode 600). - Undo:
/usr/bin/python3 /Users/richh/scripts/apply_mcp_disable_v1.0.py --rollback "/Users/richh/Library/Application Support/MCPFleetDisable/backups/20260830-1648/manifest.json" --expected-host rdmbair15m5.
Outstanding
- Already-open Claude Desktop sessions were not terminated and may retain their old in-memory tool registry until the app's normal next restart.
- Eventual uninstall, cache cleanup, or authentication cleanup requires a separate owner decision.