mcp

MCP

registerCancelJobTool()

function registerCancelJobTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/cancel-job-tool.ts:170

Parameters

server

McpServer

deps

BaseMcpToolDeps

Returns

void


registerConsensusVoteTool()

function registerConsensusVoteTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote.ts:1379

Registers the consensus_vote tool with the MCP server. Uses createSecureHandler (Issue #531) with timeout protection (Issue #271).

Parameters

server

McpServer

deps

ConsensusVoteDeps

Returns

void


registerCreateExpertTool()

function registerCreateExpertTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/create-expert.ts:321

Registers the create_expert tool with the MCP server.

Uses createSecureHandler for standardized security middleware (Issue #531). Includes timeout protection for CVE-2026-0621 mitigation (Issue #271).

Parameters

server

McpServer

MCP server instance

deps

CreateExpertDeps

Tool dependencies

Returns

void


registerDelegateToModelTool()

function registerDelegateToModelTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model.ts:298

Registers the delegate_to_model tool with the MCP server.

Uses createSecureHandler for standardized security middleware (Issue #531). Includes timeout protection for CVE-2026-0621 mitigation (Issue #271).

Parameters

server

McpServer

MCP server instance

deps

DelegateDeps

Dependencies

Returns

void


registerExecuteExpertTool()

function registerExecuteExpertTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/execute-expert.ts:671

Registers the execute_expert tool with the MCP server.

Uses MCP Tasks primitive (SEP-1686) via registerToolTask for async execution. taskSupport: ‘optional’ preserves sync fallback for clients without task support.

NOT wrapped by createSecureHandler or wrapToolWithTimeout (#4981). Of the 46 tool modules this is the only one outside the standard middleware stack: it registers through registerToolTask, so it creates no RequestContext, emits no Tool invocation started pair, and no tool-audit record. An earlier version of this comment claimed it used createSecureHandler (Issue #531) and that it carried the #271 timeout protection; neither is true as wired. Whether the tasks primitive can take those wrappers is part of #4978.

Parameters

server

McpServer

MCP server instance

deps

ExecuteExpertDeps

Tool dependencies

Returns

void


registerExecuteSpecTool()

function registerExecuteSpecTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/execute-spec-tool.ts:202

Registers the execute_spec tool with an MCP server.

Parameters

server

McpServer

deps

BaseMcpToolDeps

Returns

void


registerExtractSymbolsTool()

function registerExtractSymbolsTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/extract-symbols-tool.ts:353

Parameters

server

McpServer

deps

BaseMcpToolDeps

Returns

void


registerGetJobResultTool()

function registerGetJobResultTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/get-job-result-tool.ts:131

Parameters

server

McpServer

deps

BaseMcpToolDeps

Returns

void


registerImprovementReviewTool()

function registerImprovementReviewTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/improvement-review.ts:1057

Parameters

server

McpServer

deps

BaseMcpToolDeps

Returns

void


registerIssueTriageTool()

function registerIssueTriageTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/issue-triage-tool.ts:186

Registers the issue_triage tool with the MCP server. Uses createSecureHandler for rate limiting and input sanitization.

Parameters

server

McpServer

deps

BaseMcpToolDeps

Returns

void


registerListExpertsTool()

function registerListExpertsTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/list-experts.ts:181

Registers the list_experts tool with the MCP server.

Uses createSecureHandler for standardized security middleware (Issue #531). Includes timeout protection for CVE-2026-0621 mitigation (Issue #271).

Parameters

server

McpServer

MCP server instance

deps

BaseMcpToolDeps

Tool dependencies

Returns

void


registerListJobsTool()

function registerListJobsTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/list-jobs-tool.ts:155

Parameters

server

McpServer

deps

BaseMcpToolDeps

Returns

void


registerListWorkflowsTool()

function registerListWorkflowsTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/list-workflows.ts:163

Registers the list_workflows tool with the MCP server.

Uses createSecureHandler for standardized security middleware (Issue #531). Includes timeout protection for CVE-2026-0621 mitigation (Issue #271).

Parameters

server

McpServer

MCP server instance

deps

ListWorkflowsDeps

Tool dependencies

Returns

void


registerMemoryQueryTool()

function registerMemoryQueryTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/memory-query.ts:285

Registers the memory_query tool with the MCP server.

Parameters

server

McpServer

MCP server instance

deps

BaseMcpToolDeps

Tool dependencies

Returns

void


registerMemoryStatsTool()

function registerMemoryStatsTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/memory-stats.ts:320

Registers the memory_stats tool with the MCP server.

Parameters

server

McpServer

MCP server instance

deps

BaseMcpToolDeps

Tool dependencies

Returns

void


registerMemoryWriteTool()

function registerMemoryWriteTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/memory-write.ts:433

Registers the memory_write tool with the MCP server.

Parameters

server

McpServer

MCP server instance

deps

BaseMcpToolDeps

Tool dependencies

Returns

void


registerOrchestrateTool()

function registerOrchestrateTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/orchestrate.ts:1486

Registers the orchestrate tool with the MCP server. Uses createSecureHandler (Issue #531) with timeout protection (Issue #271).

Parameters

server

McpServer

deps

OrchestrateDeps

Returns

void


registerPrReviewTool()

function registerPrReviewTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:687

Parameters

server

McpServer

deps

PrReviewDeps

Returns

void


registerQueryTraceTool()

function registerQueryTraceTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/query-trace-tool.ts:288

Parameters

server

McpServer

deps

BaseMcpToolDeps

Returns

void


registerRegistryImportTool()

function registerRegistryImportTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/registry-import-tool.ts:63

Parameters

server

McpServer

deps

BaseMcpToolDeps

Returns

void


registerRepoAnalyzeTool()

function registerRepoAnalyzeTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze-tool.ts:60

Parameters

server

McpServer

deps

BaseMcpToolDeps

Returns

void


registerRepoSecurityPlanTool()

function registerRepoSecurityPlanTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-tool.ts:59

Parameters

server

McpServer

deps

BaseMcpToolDeps

Returns

void


registerResearchAddSourceTool()

function registerResearchAddSourceTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/research-add-source.ts:293

Parameters

server

McpServer

deps

BaseMcpToolDeps

Returns

void


registerResearchAddTool()

function registerResearchAddTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/research-add.ts:205

Registers the research_add tool with the MCP server.

Parameters

server

McpServer

MCP server instance

deps

BaseMcpToolDeps

Tool dependencies

Returns

void


registerResearchAnalyzeTool()

function registerResearchAnalyzeTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/research-analyze.ts:430

Registers the research_analyze tool with the MCP server.

Parameters

server

McpServer

MCP server instance

deps

BaseMcpToolDeps

Tool dependencies

Returns

void


registerResearchCatalogReviewTool()

function registerResearchCatalogReviewTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/research-catalog-review.ts:269

Registers the research_catalog_review tool with the MCP server.

Parameters

server

McpServer

MCP server instance

deps

BaseMcpToolDeps

Tool dependencies

Returns

void


registerResearchDiscoverTool()

function registerResearchDiscoverTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/research-discover.ts:664

Registers the research_discover tool with the MCP server.

Parameters

server

McpServer

MCP server instance

deps

BaseMcpToolDeps

Tool dependencies

Returns

void


registerResearchQueryTool()

function registerResearchQueryTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/research-query.ts:298

Registers the research_query tool with the MCP server.

Parameters

server

McpServer

MCP server instance

deps

BaseMcpToolDeps

Tool dependencies

Returns

void


registerResearchSynthesizeTool()

function registerResearchSynthesizeTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/research-synthesize.ts:97

Registers the research_synthesize tool with the MCP server.

Parameters

server

McpServer

MCP server instance

deps

BaseMcpToolDeps

Tool dependencies

Returns

void


registerRunGraphWorkflowTool()

function registerRunGraphWorkflowTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow.ts:378

Registers the run_graph_workflow tool with an MCP server.

Parameters

server

McpServer

deps

RunGraphWorkflowDeps

Returns

void


registerRunWorkflowTool()

function registerRunWorkflowTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow.ts:506

Register the run_workflow tool with an MCP server.

Uses createSecureHandler for standardized security middleware (Issue #531). Includes timeout protection for CVE-2026-0621 mitigation (Issue #271).

Parameters

server

McpServer

MCP server instance

deps

RunWorkflowDeps

Tool dependencies

Returns

void


registerSearchCodebaseTool()

function registerSearchCodebaseTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/search-codebase-tool.ts:296

Parameters

server

McpServer

deps

BaseMcpToolDeps

Returns

void


registerSearchUsagesTool()

function registerSearchUsagesTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/search-usages-tool.ts:327

Parameters

server

McpServer

deps

BaseMcpToolDeps

Returns

void


registerWeatherReportTool()

function registerWeatherReportTool(server, deps): void;

Defined in: packages/nexus-agents/src/mcp/tools/weather-report-tool.ts:100

Parameters

server

McpServer

deps

BaseMcpToolDeps

Returns

void

Other

McpRateLimiter

Defined in: packages/nexus-agents/src/mcp/middleware/rate-limiter.ts:66

Token bucket rate limiter implementation.

The token bucket algorithm allows for bursting up to the capacity, while maintaining a steady-state rate equal to the refill rate.

Example

const limiter = new RateLimiter({
  capacity: 100,
  refillRate: 10,
  refillIntervalMs: 1000,
});

if (limiter.tryAcquire()) {
  // Proceed with operation
} else {
  // Rate limited, reject or queue
}

Constructors

Constructor
new McpRateLimiter(config): McpRateLimiter;

Defined in: packages/nexus-agents/src/mcp/middleware/rate-limiter.ts:75

Parameters
config

McpRateLimiterConfig

Returns

McpRateLimiter

Methods

getState()
getState(): RateLimiterState;

Defined in: packages/nexus-agents/src/mcp/middleware/rate-limiter.ts:144

Gets the current state of the rate limiter.

Returns

RateLimiterState

The current rate limiter state

reset()
reset(): void;

Defined in: packages/nexus-agents/src/mcp/middleware/rate-limiter.ts:161

Resets the rate limiter to full capacity. Useful for testing or after configuration changes.

Returns

void

tryAcquire()
tryAcquire(count?): boolean;

Defined in: packages/nexus-agents/src/mcp/middleware/rate-limiter.ts:120

Attempts to acquire a token.

Parameters
count?

number = 1

Number of tokens to acquire (default: 1)

Returns

boolean

True if tokens were acquired, false if rate limited


OrchestrationError

Defined in: packages/nexus-agents/src/mcp/tools/orchestrate-types.ts:227

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports

Extends

Constructors

Constructor
new OrchestrationError(message, options?): OrchestrationError;

Defined in: packages/nexus-agents/src/mcp/tools/orchestrate-types.ts:228

Parameters
message

string

options?
cause?

Error

context?

Record<string, unknown>

Returns

OrchestrationError

Overrides

AgentError.constructor

Properties

cause
readonly cause: Error | undefined;

Defined in: packages/nexus-agents/src/core/errors.ts:105

Inherited from

AgentError.cause

code
readonly code: ErrorCode;

Defined in: packages/nexus-agents/src/core/errors.ts:103

Inherited from

AgentError.code

context
readonly context: Record<string, unknown> | undefined;

Defined in: packages/nexus-agents/src/core/errors.ts:104

Inherited from

AgentError.context

message
message: string;

Defined in: node_modules/.pnpm/typescript@6.0.3/node_modules/typescript/lib/lib.es5.d.ts:1075

Inherited from

AgentError.message

name
name: string;

Defined in: node_modules/.pnpm/typescript@6.0.3/node_modules/typescript/lib/lib.es5.d.ts:1074

Inherited from

AgentError.name

stack?
optional stack?: string;

Defined in: node_modules/.pnpm/typescript@6.0.3/node_modules/typescript/lib/lib.es5.d.ts:1076

Inherited from

AgentError.stack

stackTraceLimit
static stackTraceLimit: number;

Defined in: node_modules/.pnpm/@types+node@25.9.8/node_modules/@types/node/globals.d.ts:67

The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).

The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.

If set to a non-number value, or set to a negative number, stack traces will not capture any frames.

Inherited from

AgentError.stackTraceLimit

Methods

toJSON()
toJSON(): SerializedError;

Defined in: packages/nexus-agents/src/core/errors.ts:121

Serializes the error to a JSON-safe object.

Returns

SerializedError

Inherited from

AgentError.toJSON

captureStackTrace()
static captureStackTrace(targetObject, constructorOpt?): void;

Defined in: node_modules/.pnpm/@types+node@25.9.8/node_modules/@types/node/globals.d.ts:51

Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.

const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack;  // Similar to `new Error().stack`

The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.

The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.

The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:

function a() {
  b();
}

function b() {
  c();
}

function c() {
  // Create an error without stack trace to avoid calculating the stack trace twice.
  const { stackTraceLimit } = Error;
  Error.stackTraceLimit = 0;
  const error = new Error();
  Error.stackTraceLimit = stackTraceLimit;

  // Capture the stack trace above function b
  Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
  throw error;
}

a();
Parameters
targetObject

object

constructorOpt?

Function

Returns

void

Inherited from

AgentError.captureStackTrace

prepareStackTrace()
static prepareStackTrace(err, stackTraces): any;

Defined in: node_modules/.pnpm/@types+node@25.9.8/node_modules/@types/node/globals.d.ts:55

Parameters
err

Error

stackTraces

CallSite[]

Returns

any

See

https://v8.dev/docs/stack-trace-api#customizing-stack-traces

Inherited from

AgentError.prepareStackTrace


OrchestrationUnavailableError

Defined in: packages/nexus-agents/src/mcp/tools/orchestrate-types.ts:235

Error when orchestration is unavailable (no model adapter). Issue #554.

Extends

Constructors

Constructor
new OrchestrationUnavailableError(message, options?): OrchestrationUnavailableError;

Defined in: packages/nexus-agents/src/mcp/tools/orchestrate-types.ts:236

Parameters
message

string

options?
cause?

Error

context?

Record<string, unknown>

Returns

OrchestrationUnavailableError

Overrides

AgentError.constructor

Properties

cause
readonly cause: Error | undefined;

Defined in: packages/nexus-agents/src/core/errors.ts:105

Inherited from

AgentError.cause

code
readonly code: ErrorCode;

Defined in: packages/nexus-agents/src/core/errors.ts:103

Inherited from

AgentError.code

context
readonly context: Record<string, unknown> | undefined;

Defined in: packages/nexus-agents/src/core/errors.ts:104

Inherited from

AgentError.context

message
message: string;

Defined in: node_modules/.pnpm/typescript@6.0.3/node_modules/typescript/lib/lib.es5.d.ts:1075

Inherited from

AgentError.message

name
name: string;

Defined in: node_modules/.pnpm/typescript@6.0.3/node_modules/typescript/lib/lib.es5.d.ts:1074

Inherited from

AgentError.name

stack?
optional stack?: string;

Defined in: node_modules/.pnpm/typescript@6.0.3/node_modules/typescript/lib/lib.es5.d.ts:1076

Inherited from

AgentError.stack

stackTraceLimit
static stackTraceLimit: number;

Defined in: node_modules/.pnpm/@types+node@25.9.8/node_modules/@types/node/globals.d.ts:67

The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).

The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.

If set to a non-number value, or set to a negative number, stack traces will not capture any frames.

Inherited from

AgentError.stackTraceLimit

Methods

toJSON()
toJSON(): SerializedError;

Defined in: packages/nexus-agents/src/core/errors.ts:121

Serializes the error to a JSON-safe object.

Returns

SerializedError

Inherited from

AgentError.toJSON

captureStackTrace()
static captureStackTrace(targetObject, constructorOpt?): void;

Defined in: node_modules/.pnpm/@types+node@25.9.8/node_modules/@types/node/globals.d.ts:51

Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.

const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack;  // Similar to `new Error().stack`

The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.

The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.

The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:

function a() {
  b();
}

function b() {
  c();
}

function c() {
  // Create an error without stack trace to avoid calculating the stack trace twice.
  const { stackTraceLimit } = Error;
  Error.stackTraceLimit = 0;
  const error = new Error();
  Error.stackTraceLimit = stackTraceLimit;

  // Capture the stack trace above function b
  Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
  throw error;
}

a();
Parameters
targetObject

object

constructorOpt?

Function

Returns

void

Inherited from

AgentError.captureStackTrace

prepareStackTrace()
static prepareStackTrace(err, stackTraces): any;

Defined in: node_modules/.pnpm/@types+node@25.9.8/node_modules/@types/node/globals.d.ts:55

Parameters
err

Error

stackTraces

CallSite[]

Returns

any

See

https://v8.dev/docs/stack-trace-api#customizing-stack-traces

Inherited from

AgentError.prepareStackTrace


PolicyError

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:121

Policy error for authorization failures.

Extends

Constructors

Constructor
new PolicyError(message, decision): PolicyError;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:124

Parameters
message

string

decision

FirewallPolicyDecision

Returns

PolicyError

Overrides

SecurityError.constructor

Properties

cause
readonly cause: Error | undefined;

Defined in: packages/nexus-agents/src/core/errors.ts:105

Inherited from

SecurityError.cause

code
readonly code: ErrorCode;

Defined in: packages/nexus-agents/src/core/errors.ts:103

Inherited from

SecurityError.code

context
readonly context: Record<string, unknown> | undefined;

Defined in: packages/nexus-agents/src/core/errors.ts:104

Inherited from

SecurityError.context

decision
readonly decision: FirewallPolicyDecision;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:122

message
message: string;

Defined in: node_modules/.pnpm/typescript@6.0.3/node_modules/typescript/lib/lib.es5.d.ts:1075

Inherited from

SecurityError.message

name
name: string;

Defined in: node_modules/.pnpm/typescript@6.0.3/node_modules/typescript/lib/lib.es5.d.ts:1074

Inherited from

SecurityError.name

stack?
optional stack?: string;

Defined in: node_modules/.pnpm/typescript@6.0.3/node_modules/typescript/lib/lib.es5.d.ts:1076

Inherited from

SecurityError.stack

stackTraceLimit
static stackTraceLimit: number;

Defined in: node_modules/.pnpm/@types+node@25.9.8/node_modules/@types/node/globals.d.ts:67

The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).

The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.

If set to a non-number value, or set to a negative number, stack traces will not capture any frames.

Inherited from

SecurityError.stackTraceLimit

Methods

toJSON()
toJSON(): SerializedError;

Defined in: packages/nexus-agents/src/core/errors.ts:121

Serializes the error to a JSON-safe object.

Returns

SerializedError

Inherited from

SecurityError.toJSON

captureStackTrace()
static captureStackTrace(targetObject, constructorOpt?): void;

Defined in: node_modules/.pnpm/@types+node@25.9.8/node_modules/@types/node/globals.d.ts:51

Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.

const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack;  // Similar to `new Error().stack`

The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.

The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.

The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:

function a() {
  b();
}

function b() {
  c();
}

function c() {
  // Create an error without stack trace to avoid calculating the stack trace twice.
  const { stackTraceLimit } = Error;
  Error.stackTraceLimit = 0;
  const error = new Error();
  Error.stackTraceLimit = stackTraceLimit;

  // Capture the stack trace above function b
  Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
  throw error;
}

a();
Parameters
targetObject

object

constructorOpt?

Function

Returns

void

Inherited from

SecurityError.captureStackTrace

prepareStackTrace()
static prepareStackTrace(err, stackTraces): any;

Defined in: node_modules/.pnpm/@types+node@25.9.8/node_modules/@types/node/globals.d.ts:55

Parameters
err

Error

stackTraces

CallSite[]

Returns

any

See

https://v8.dev/docs/stack-trace-api#customizing-stack-traces

Inherited from

SecurityError.prepareStackTrace


PolicyFirewall

Defined in: packages/nexus-agents/src/mcp/middleware/policy.ts:59

Policy firewall that evaluates rules to authorize or deny operations.

Rules are evaluated in order. The first rule that denies the operation stops evaluation and returns the denial. If all rules pass, the operation is allowed.

Example

const firewall = new PolicyFirewall({ mode: 'enforce' });

// Add rules
firewall.addRule(denyMutationsWithoutModeRule);
firewall.addRule(safePathsRule);

// Evaluate
const decision = firewall.evaluate({
  toolName: 'write_file',
  args: { path: '/etc/passwd' },
  mode: 'read-only',
});

if (!decision.allowed) {
  console.error(`Denied: ${decision.reason}`);
}

Implements

Constructors

Constructor
new PolicyFirewall(config?): PolicyFirewall;

Defined in: packages/nexus-agents/src/mcp/middleware/policy.ts:64

Parameters
config?

PolicyFirewallConfig

Returns

PolicyFirewall

Methods

addRule()
addRule(rule): void;

Defined in: packages/nexus-agents/src/mcp/middleware/policy.ts:165

Adds a policy rule to the firewall.

Parameters
rule

FirewallPolicyRule

The rule to add

Returns

void

Implementation of

IPolicyFirewall.addRule

evaluate()
evaluate(ctx): FirewallPolicyDecision;

Defined in: packages/nexus-agents/src/mcp/middleware/policy.ts:90

Evaluates all policy rules against the given context.

Rules are evaluated in order. The first rule that denies stops evaluation and returns the denial decision.

Parameters
ctx

FirewallPolicyContext

The policy context to evaluate

Returns

FirewallPolicyDecision

The policy decision

Implementation of

IPolicyFirewall.evaluate

getMode()
getMode(): PolicyMode;

Defined in: packages/nexus-agents/src/mcp/middleware/policy.ts:218

Gets the current policy enforcement mode.

Returns

PolicyMode

The current mode

Implementation of

IPolicyFirewall.getMode

getRules()
getRules(): readonly FirewallPolicyRule[];

Defined in: packages/nexus-agents/src/mcp/middleware/policy.ts:198

Gets all registered policy rules.

Returns

readonly FirewallPolicyRule[]

A readonly array of policy rules

Implementation of

IPolicyFirewall.getRules

removeRule()
removeRule(name): boolean;

Defined in: packages/nexus-agents/src/mcp/middleware/policy.ts:183

Removes a policy rule by name.

Parameters
name

string

The name of the rule to remove

Returns

boolean

True if the rule was found and removed

Implementation of

IPolicyFirewall.removeRule

setMode()
setMode(mode): void;

Defined in: packages/nexus-agents/src/mcp/middleware/policy.ts:207

Sets the policy enforcement mode.

Parameters
mode

PolicyMode

The new enforcement mode

Returns

void

Implementation of

IPolicyFirewall.setMode


AgentVoteSummary

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:348

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports

Properties

confidence
confidence: number;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:351

decision
decision: "approve" | "reject" | "abstain";

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:350

error
error: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:355

True when this vote was generated from an error (Issue #815).

fallback?
optional fallback?: SeatFallback;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:389

Present only when this seat answered on a different CLI or model than it was assigned (#6115): where it was meant to answer and the adapter error class that moved it. panelDiversity.fallbacks counts these seats.

modelUsed?
optional modelUsed?: string;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:362

Model this seat ran on (Issue #817). Populated since #6606 from the seat’s resolved model; absent when the seat resolved none (an errored seat that never reached a model, or the lazy-detection placeholder). Clipped to MODEL_USED_MAX_CHARS to fit the advertised output schema.

reasoning
reasoning: string;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:352

rejectionCategories?
optional rejectionCategories?: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:364

Structured rejection categories for reject→refine→re-vote loops (Issue #1213).

retried?
optional retried?: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:373

True when this seat was recovered by the per-role retry (#6050).

Present only when true. A retried seat is weaker evidence than a first-pass one — the model was unavailable or timed out — so a caller reading a panel result should be able to see that “7 of 7 answered” and “6 answered, 1 recovered” are different facts.

retriedFrom?
optional retriedFrom?: RetriedFrom;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:395

Present only when the per-role retry REPLACED this seat (#6246): the first pass’s source and, when it had one, its clipped error string. retried says a recovery happened; this says what it recovered from.

role
role: string;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:349

selectedOption?
optional selectedOption?: string;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:376

Which declared option this voter chose (#4472). Absent when the proposal declared none, or the voter’s selection matched none of them.

simulated
simulated: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:353

unverifiable?
optional unverifiable?: true;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:383

True when this seat could not read the artifact (#6094). Present only when true. Its decision is always abstain; voteCounts.unverifiable counts these seats separately so a blind seat is never read as a considered abstention.


BaseMcpToolDeps

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:31

Common dependency interface shared by all MCP tool handlers.

Tool-specific deps interfaces should extend this base. (Source: Issue #1439 — DRY extraction of 25 duplicated Deps interfaces)

Extended by

Properties

logger?
optional logger?: ILogger;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:33

Optional logger

rateLimiter
rateLimiter: McpRateLimiter;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:35

Rate limiter for throttling tool calls (required)

security?
optional security?: {
  allowedPaths: string[];
  audit?: {
     enabled: boolean;
     enableHashChain: boolean;
     logDir?: string;
     maxFiles: number;
     maxFileSizeBytes: number;
     minSeverity: "critical" | "info" | "warning";
  };
  auth?: {
     enabled: boolean;
     method: "token" | "oauth2";
     tokenFile?: string;
     tokenHeader: string;
  };
  blockedPatterns: string[];
  policy?: {
     defaultMode: "read-only" | "read-write";
     policyMode: "warn" | "enforce";
  };
  rateLimit: {
     enabled: boolean;
     perTool?: Record<string, {
        capacity: number;
        refillIntervalMs: number;
        refillRate: number;
     }>;
     requestsPerMinute: number;
  };
  sandbox?: {
     dockerImage?: string;
     fallbackToPolicy: boolean;
     mode: "policy" | "none" | "container";
     networkEnabled: boolean;
  };
  secretsFile?: string;
  timeout?: {
     defaultTimeoutMs: number;
     enableLogging: boolean;
     maxTimeoutMs: number;
     perToolTimeout?: Record<string, number>;
     uriValidation: boolean;
  };
  toolAllowlist?: string[];
};

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:37

Security configuration (includes timeout settings)

allowedPaths
allowedPaths: string[];
audit?
optional audit?: {
  enabled: boolean;
  enableHashChain: boolean;
  logDir?: string;
  maxFiles: number;
  maxFileSizeBytes: number;
  minSeverity: "critical" | "info" | "warning";
};

Audit logging configuration (Issue #740 Phase 2).

The block is optional and the inner defaults only apply when it is present: a config with no audit: block is audit-OFF (initializeAuditLogger returns null and startup warns). config init writes the block explicitly so a generated config is on by default (#5632).

audit.enabled
enabled: boolean;

Enable audit logging (default when the block is present: true)

audit.enableHashChain
enableHashChain: boolean;

Enable tamper-evident hash chain (default: true)

audit.logDir?
optional logDir?: string;

Log directory (default: ~/.nexus-agents/audit)

audit.maxFiles
maxFiles: number;

Maximum number of log files to retain (default: 10)

audit.maxFileSizeBytes
maxFileSizeBytes: number;

Maximum log file size in bytes (default: 10MB)

audit.minSeverity
minSeverity: "critical" | "info" | "warning";

Minimum severity to log (default: ‘info’)

auth?
optional auth?: {
  enabled: boolean;
  method: "token" | "oauth2";
  tokenFile?: string;
  tokenHeader: string;
};

Authentication configuration (Issue #739)

auth.enabled
enabled: boolean;

Enable authentication for network-exposed transports (default: true)

auth.method
method: "token" | "oauth2";

Authentication method (default: ‘token’)

auth.tokenFile?
optional tokenFile?: string;

Token file path (default: ~/.nexus-agents/auth/server-token)

auth.tokenHeader
tokenHeader: string;

Header name for bearer token (default: ‘Authorization’)

blockedPatterns
blockedPatterns: string[];
policy?
optional policy?: {
  defaultMode: "read-only" | "read-write";
  policyMode: "warn" | "enforce";
};

Policy firewall configuration

policy.defaultMode
defaultMode: "read-only" | "read-write";

Execution mode for tool operations (default: ‘read-write’; ‘read-only’ is the opt-in lock, #6431)

policy.policyMode
policyMode: "warn" | "enforce";

Policy enforcement mode (default: ‘enforce’)

rateLimit
rateLimit: {
  enabled: boolean;
  perTool?: Record<string, {
     capacity: number;
     refillIntervalMs: number;
     refillRate: number;
  }>;
  requestsPerMinute: number;
};
rateLimit.enabled
enabled: boolean;
rateLimit.perTool?
optional perTool?: Record<string, {
  capacity: number;
  refillIntervalMs: number;
  refillRate: number;
}>;

Per-tool rate limits (Issue #274 Phase 2)

rateLimit.requestsPerMinute
requestsPerMinute: number;
sandbox?
optional sandbox?: {
  dockerImage?: string;
  fallbackToPolicy: boolean;
  mode: "policy" | "none" | "container";
  networkEnabled: boolean;
};

Sandbox execution configuration (Issue #175)

sandbox.dockerImage?
optional dockerImage?: string;

Docker image to use in container mode (default: ‘node:22-alpine’)

sandbox.fallbackToPolicy
fallbackToPolicy: boolean;

Fall back to policy mode if container mode unavailable (default: true)

sandbox.mode
mode: "policy" | "none" | "container";

Sandbox execution mode (default: ‘policy’)

sandbox.networkEnabled
networkEnabled: boolean;

Enable network access in container mode (default: false)

secretsFile?
optional secretsFile?: string;
timeout?
optional timeout?: {
  defaultTimeoutMs: number;
  enableLogging: boolean;
  maxTimeoutMs: number;
  perToolTimeout?: Record<string, number>;
  uriValidation: boolean;
};

Timeout configuration (Issue #271, CVE-2026-0621)

timeout.defaultTimeoutMs
defaultTimeoutMs: number;

Default timeout in milliseconds (default: 30000)

timeout.enableLogging
enableLogging: boolean;

Whether to log timeout events (default: true)

timeout.maxTimeoutMs
maxTimeoutMs: number;

Maximum timeout in milliseconds (default: 300000)

timeout.perToolTimeout?
optional perToolTimeout?: Record<string, number>;

Per-tool timeout overrides in milliseconds (Issue #657)

timeout.uriValidation
uriValidation: boolean;

Enable URI validation to prevent ReDoS (default: true)

toolAllowlist?
optional toolAllowlist?: string[];

Tool allowlist — when set, only listed tools are registered (Issue #740)


CancelJobResponse

Defined in: packages/nexus-agents/src/mcp/tools/cancel-job-tool.ts:69

Outcome envelope. status discriminates the four cases.

Properties

jobId
readonly jobId: string;

Defined in: packages/nexus-agents/src/mcp/tools/cancel-job-tool.ts:70

message
readonly message: string;

Defined in: packages/nexus-agents/src/mcp/tools/cancel-job-tool.ts:76

Human-readable explanation matching the outcome.

outcome
readonly outcome: "cancelled" | "already_complete" | "already_cancelled" | "unknown_job";

Defined in: packages/nexus-agents/src/mcp/tools/cancel-job-tool.ts:72

Outcome category — see module docstring.

status?
readonly optional status?: "failed" | "cancelled" | "pending" | "complete";

Defined in: packages/nexus-agents/src/mcp/tools/cancel-job-tool.ts:74

The terminal status now on disk (after this call). Absent for unknown_job.


CapabilityProfile

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:31

Model capability profile for routing decisions.

Properties

codeGeneration
readonly codeGeneration: number;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:37

Code generation quality (0-10)

contextWindow
readonly contextWindow: number;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:35

Maximum context window in tokens

cost
readonly cost: number;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:41

Cost efficiency (0-10, higher = cheaper)

reasoning
readonly reasoning: number;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:33

Complex reasoning ability (0-10)

speed
readonly speed: number;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:39

Response latency score (0-10, higher = faster)


ConflictWarning

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:53

A conflict or redundancy warning.

Properties

recommendation
readonly recommendation: string;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:56

scanners
readonly scanners: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:54

type
readonly type: "superseded" | "redundant";

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:55


ConsensusVoteDeps

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote.ts:160

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports

Extends

Properties

gatewayAdapters?
optional gatewayAdapters?: readonly IModelAdapter[];

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote.ts:169

In-process gateway model adapters (#4040). When the server has a configured OpenAI-compatible gateway, voters route through these HTTP adapters instead of shelling out to a CLI subprocess — no per-subprocess key forwarding, and the nested-spawn deadlock (#4033) cannot occur. Omitted ⇒ CLI voter path.

logger?
optional logger?: ILogger;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:33

Optional logger

Inherited from

BaseMcpToolDeps.logger

notifier?
optional notifier?: IMcpNotifier;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote.ts:162

MCP notifier for client-visible logging (Issue #974)

rateLimiter
rateLimiter: McpRateLimiter;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:35

Rate limiter for throttling tool calls (required)

Inherited from

BaseMcpToolDeps.rateLimiter

security?
optional security?: {
  allowedPaths: string[];
  audit?: {
     enabled: boolean;
     enableHashChain: boolean;
     logDir?: string;
     maxFiles: number;
     maxFileSizeBytes: number;
     minSeverity: "critical" | "info" | "warning";
  };
  auth?: {
     enabled: boolean;
     method: "token" | "oauth2";
     tokenFile?: string;
     tokenHeader: string;
  };
  blockedPatterns: string[];
  policy?: {
     defaultMode: "read-only" | "read-write";
     policyMode: "warn" | "enforce";
  };
  rateLimit: {
     enabled: boolean;
     perTool?: Record<string, {
        capacity: number;
        refillIntervalMs: number;
        refillRate: number;
     }>;
     requestsPerMinute: number;
  };
  sandbox?: {
     dockerImage?: string;
     fallbackToPolicy: boolean;
     mode: "policy" | "none" | "container";
     networkEnabled: boolean;
  };
  secretsFile?: string;
  timeout?: {
     defaultTimeoutMs: number;
     enableLogging: boolean;
     maxTimeoutMs: number;
     perToolTimeout?: Record<string, number>;
     uriValidation: boolean;
  };
  toolAllowlist?: string[];
};

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:37

Security configuration (includes timeout settings)

allowedPaths
allowedPaths: string[];
audit?
optional audit?: {
  enabled: boolean;
  enableHashChain: boolean;
  logDir?: string;
  maxFiles: number;
  maxFileSizeBytes: number;
  minSeverity: "critical" | "info" | "warning";
};

Audit logging configuration (Issue #740 Phase 2).

The block is optional and the inner defaults only apply when it is present: a config with no audit: block is audit-OFF (initializeAuditLogger returns null and startup warns). config init writes the block explicitly so a generated config is on by default (#5632).

audit.enabled
enabled: boolean;

Enable audit logging (default when the block is present: true)

audit.enableHashChain
enableHashChain: boolean;

Enable tamper-evident hash chain (default: true)

audit.logDir?
optional logDir?: string;

Log directory (default: ~/.nexus-agents/audit)

audit.maxFiles
maxFiles: number;

Maximum number of log files to retain (default: 10)

audit.maxFileSizeBytes
maxFileSizeBytes: number;

Maximum log file size in bytes (default: 10MB)

audit.minSeverity
minSeverity: "critical" | "info" | "warning";

Minimum severity to log (default: ‘info’)

auth?
optional auth?: {
  enabled: boolean;
  method: "token" | "oauth2";
  tokenFile?: string;
  tokenHeader: string;
};

Authentication configuration (Issue #739)

auth.enabled
enabled: boolean;

Enable authentication for network-exposed transports (default: true)

auth.method
method: "token" | "oauth2";

Authentication method (default: ‘token’)

auth.tokenFile?
optional tokenFile?: string;

Token file path (default: ~/.nexus-agents/auth/server-token)

auth.tokenHeader
tokenHeader: string;

Header name for bearer token (default: ‘Authorization’)

blockedPatterns
blockedPatterns: string[];
policy?
optional policy?: {
  defaultMode: "read-only" | "read-write";
  policyMode: "warn" | "enforce";
};

Policy firewall configuration

policy.defaultMode
defaultMode: "read-only" | "read-write";

Execution mode for tool operations (default: ‘read-write’; ‘read-only’ is the opt-in lock, #6431)

policy.policyMode
policyMode: "warn" | "enforce";

Policy enforcement mode (default: ‘enforce’)

rateLimit
rateLimit: {
  enabled: boolean;
  perTool?: Record<string, {
     capacity: number;
     refillIntervalMs: number;
     refillRate: number;
  }>;
  requestsPerMinute: number;
};
rateLimit.enabled
enabled: boolean;
rateLimit.perTool?
optional perTool?: Record<string, {
  capacity: number;
  refillIntervalMs: number;
  refillRate: number;
}>;

Per-tool rate limits (Issue #274 Phase 2)

rateLimit.requestsPerMinute
requestsPerMinute: number;
sandbox?
optional sandbox?: {
  dockerImage?: string;
  fallbackToPolicy: boolean;
  mode: "policy" | "none" | "container";
  networkEnabled: boolean;
};

Sandbox execution configuration (Issue #175)

sandbox.dockerImage?
optional dockerImage?: string;

Docker image to use in container mode (default: ‘node:22-alpine’)

sandbox.fallbackToPolicy
fallbackToPolicy: boolean;

Fall back to policy mode if container mode unavailable (default: true)

sandbox.mode
mode: "policy" | "none" | "container";

Sandbox execution mode (default: ‘policy’)

sandbox.networkEnabled
networkEnabled: boolean;

Enable network access in container mode (default: false)

secretsFile?
optional secretsFile?: string;
timeout?
optional timeout?: {
  defaultTimeoutMs: number;
  enableLogging: boolean;
  maxTimeoutMs: number;
  perToolTimeout?: Record<string, number>;
  uriValidation: boolean;
};

Timeout configuration (Issue #271, CVE-2026-0621)

timeout.defaultTimeoutMs
defaultTimeoutMs: number;

Default timeout in milliseconds (default: 30000)

timeout.enableLogging
enableLogging: boolean;

Whether to log timeout events (default: true)

timeout.maxTimeoutMs
maxTimeoutMs: number;

Maximum timeout in milliseconds (default: 300000)

timeout.perToolTimeout?
optional perToolTimeout?: Record<string, number>;

Per-tool timeout overrides in milliseconds (Issue #657)

timeout.uriValidation
uriValidation: boolean;

Enable URI validation to prevent ReDoS (default: true)

toolAllowlist?
optional toolAllowlist?: string[];

Tool allowlist — when set, only listed tools are registered (Issue #740)

Inherited from

BaseMcpToolDeps.security


ConsensusVoteResponse

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:504

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports

Properties

approvalPercentage
approvalPercentage: number;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:509

contrarianCheck
contrarianCheck: "ok" | "skipped" | "errored";

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:528

#6111: the quick-mode contrarian check, reported beside the tally because voteCounts.error counts seats and the check is not one. Always present; skipped is the named empty case (see ContrarianCheckStatus).

costSummary?
optional costSummary?: DecisionCostSummary;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:575

Per-decision cost rollup (#3855): per-voter / per-model token + USD totals for this governed decision. Rides the existing response — no new MCP tool. Totals are a floor when costSummary.unmeasuredVoters > 0 (voters whose adapter reported no usage are counted as unmeasured, not a measured $0).

decision
decision: "timeout" | "rejected" | "pending" | "approved" | "no_quorum";

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:508

durationMs
durationMs: number;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:530

higherOrderMetadata?
optional higherOrderMetadata?: HigherOrderMetadata;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:546

optionOutcome?
optional optionOutcome?: {
  approverCount: number;
  leadingOption?: string;
  leadingShare: number;
  selectedCount: number;
  tally: readonly {
     count: number;
     option: string;
  }[];
  thresholdMet: boolean;
  unattributedApprovals: number;
  vetoReason?: string;
};

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:585

#4472: declared-option outcome, present only when the proposal declared options. Separate from approvalPercentage — that stays the approve/reject figure — so a caller can tell WHICH bar failed.

unattributedApprovals is load-bearing, not decoration: a share alone cannot distinguish dissent from absence, since 4 pick X + 3 unparseable reads 57% exactly like a real 4/3 split.

approverCount
approverCount: number;
leadingOption?
optional leadingOption?: string;
leadingShare
leadingShare: number;
selectedCount
selectedCount: number;
tally
tally: readonly {
  count: number;
  option: string;
}[];
thresholdMet
thresholdMet: boolean;
unattributedApprovals
unattributedApprovals: number;
vetoReason?
optional vetoReason?: string;

#4529: why the gate vetoed, present only when it did. Carried here rather than on policyReason, which means “an error policy voided this vote” — a split is a decision, not a void, and conflating them let a retry policy re-roll a panel that had already disagreed.

panelDiversity
panelDiversity: PanelDiversity;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:568

#6115: how many distinct models answered and how many seats answered somewhere other than where they were assigned. Always present, explicit zeros included — three consecutive 7-seat panels ran every seat on one model after the claude and codex seats fell over, and the response read identically to a three-model panel. panelWarning names a single-model panel of 3+ seats.

panelWarning?
optional panelWarning?: string;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:559

Set when the panel was DEGRADED (#3587): some voters errored, so the decision rests on fewer than the requested number of voters. Surfaces a silently-shrunk panel so the result isn’t read as a full-strength consensus. Absent when every requested voter returned a real vote.

policyReason?
optional policyReason?: string;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:552

Set when an error policy short-circuited the vote (#2630/#3124). Explains a rejected decision that may coexist with a high approvalPercentage — e.g. fail_closed: 1 voter(s) errored. Absent on normally-tallied votes.

project
project: ResolvedVoterProject;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:539

#6110: the project every voter was told it is judging, and how that name was decided — input (the caller’s project), derived (the working directory’s origin remote or package.json), or default (nexus-agents). Always present: a consuming repository that forgot the input sees default next to the verdict instead of a silent mis-scope.

proposal
proposal: string;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:505

simulateVotes
simulateVotes: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:531

strategy
strategy: VotingStrategy;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:507

threshold?
optional threshold?: "supermajority" | "unanimous" | "majority";

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:506

voteCounts
voteCounts: {
  abstain: number;
  approve: number;
  error: number;
  reject: number;
  unverifiable: number;
};

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:516

unverifiable (#6094) counts seats that answered without reading the artifact. Those seats are ALSO inside abstain (their legacy decision); the bucket is always present, explicit 0 included — an absent key would read as health.

abstain
abstain: number;
approve
approve: number;
error
error: number;
reject
reject: number;
unverifiable
unverifiable: number;
voteRecordId?
optional voteRecordId?: string;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:624

#5130: the persisted record’s id, present only when voteRecordPersisted is true. The caller-commits script (scripts/append-ratification-record.ts --record-id) is keyed on it, and a job result carries it so --job <jobId> can find the record. Without it nothing downstream of the vote could name the record it produced.

voteRecordNote?
optional voteRecordNote?: string;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:616

#3991: present only when voteRecordPersisted is false — the actionable reason the record was not written (e.g. the data dir is unwritable → fix permissions or set NEXUS_VOTE_RECORDS_PATH to a writable path).

voteRecordPersisted
voteRecordPersisted: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:610

#3991: whether the authentic vote record (#3897) was persisted at vote time. Post-#3991 the runtime ledger routes through nexusDataPath under governance/, so a writable .nexus-agents/governance/ location almost always exists and true is the normal case. false means the persist was skipped (all votes simulated) or the write failed (data dir unwritable) — see voteRecordNote. Surfaces to the MCP caller what was previously only a server-side WARN.

votes
votes: AgentVoteSummary[];

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:529

workspace?
optional workspace?: string;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:545

#6258: the working directory every seat was pointed at — the caller’s checkout, else the server’s process.cwd(). Present-only: absent when no live seat ran (a simulated panel) or the result bypassed executeVoting.


CoverageAnalysis

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:60

Coverage analysis by category.

Properties

category
readonly category: string;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:61

covered
readonly covered: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:62

scanners
readonly scanners: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:63


CreateExpertDeps

Defined in: packages/nexus-agents/src/mcp/tools/create-expert.ts:102

Dependencies for create_expert tool.

Extends

Properties

cliCache?
optional cliCache?: ICliDetectionCache;

Defined in: packages/nexus-agents/src/mcp/tools/create-expert.ts:108

Optional CLI detection cache for checking available CLIs (Issue #747)

expertFactory
expertFactory: McpExpertFactory;

Defined in: packages/nexus-agents/src/mcp/tools/create-expert.ts:104

Expert factory for creating experts

expertRegistry
expertRegistry: Map<string, Expert>;

Defined in: packages/nexus-agents/src/mcp/tools/create-expert.ts:106

Registry to track created experts

logger?
optional logger?: ILogger;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:33

Optional logger

Inherited from

BaseMcpToolDeps.logger

modelAdapter?
optional modelAdapter?: IModelAdapter;

Defined in: packages/nexus-agents/src/mcp/tools/create-expert.ts:110

Model adapter for expert execution (Issue #808)

rateLimiter
rateLimiter: McpRateLimiter;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:35

Rate limiter for throttling tool calls (required)

Inherited from

BaseMcpToolDeps.rateLimiter

security?
optional security?: {
  allowedPaths: string[];
  audit?: {
     enabled: boolean;
     enableHashChain: boolean;
     logDir?: string;
     maxFiles: number;
     maxFileSizeBytes: number;
     minSeverity: "critical" | "info" | "warning";
  };
  auth?: {
     enabled: boolean;
     method: "token" | "oauth2";
     tokenFile?: string;
     tokenHeader: string;
  };
  blockedPatterns: string[];
  policy?: {
     defaultMode: "read-only" | "read-write";
     policyMode: "warn" | "enforce";
  };
  rateLimit: {
     enabled: boolean;
     perTool?: Record<string, {
        capacity: number;
        refillIntervalMs: number;
        refillRate: number;
     }>;
     requestsPerMinute: number;
  };
  sandbox?: {
     dockerImage?: string;
     fallbackToPolicy: boolean;
     mode: "policy" | "none" | "container";
     networkEnabled: boolean;
  };
  secretsFile?: string;
  timeout?: {
     defaultTimeoutMs: number;
     enableLogging: boolean;
     maxTimeoutMs: number;
     perToolTimeout?: Record<string, number>;
     uriValidation: boolean;
  };
  toolAllowlist?: string[];
};

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:37

Security configuration (includes timeout settings)

allowedPaths
allowedPaths: string[];
audit?
optional audit?: {
  enabled: boolean;
  enableHashChain: boolean;
  logDir?: string;
  maxFiles: number;
  maxFileSizeBytes: number;
  minSeverity: "critical" | "info" | "warning";
};

Audit logging configuration (Issue #740 Phase 2).

The block is optional and the inner defaults only apply when it is present: a config with no audit: block is audit-OFF (initializeAuditLogger returns null and startup warns). config init writes the block explicitly so a generated config is on by default (#5632).

audit.enabled
enabled: boolean;

Enable audit logging (default when the block is present: true)

audit.enableHashChain
enableHashChain: boolean;

Enable tamper-evident hash chain (default: true)

audit.logDir?
optional logDir?: string;

Log directory (default: ~/.nexus-agents/audit)

audit.maxFiles
maxFiles: number;

Maximum number of log files to retain (default: 10)

audit.maxFileSizeBytes
maxFileSizeBytes: number;

Maximum log file size in bytes (default: 10MB)

audit.minSeverity
minSeverity: "critical" | "info" | "warning";

Minimum severity to log (default: ‘info’)

auth?
optional auth?: {
  enabled: boolean;
  method: "token" | "oauth2";
  tokenFile?: string;
  tokenHeader: string;
};

Authentication configuration (Issue #739)

auth.enabled
enabled: boolean;

Enable authentication for network-exposed transports (default: true)

auth.method
method: "token" | "oauth2";

Authentication method (default: ‘token’)

auth.tokenFile?
optional tokenFile?: string;

Token file path (default: ~/.nexus-agents/auth/server-token)

auth.tokenHeader
tokenHeader: string;

Header name for bearer token (default: ‘Authorization’)

blockedPatterns
blockedPatterns: string[];
policy?
optional policy?: {
  defaultMode: "read-only" | "read-write";
  policyMode: "warn" | "enforce";
};

Policy firewall configuration

policy.defaultMode
defaultMode: "read-only" | "read-write";

Execution mode for tool operations (default: ‘read-write’; ‘read-only’ is the opt-in lock, #6431)

policy.policyMode
policyMode: "warn" | "enforce";

Policy enforcement mode (default: ‘enforce’)

rateLimit
rateLimit: {
  enabled: boolean;
  perTool?: Record<string, {
     capacity: number;
     refillIntervalMs: number;
     refillRate: number;
  }>;
  requestsPerMinute: number;
};
rateLimit.enabled
enabled: boolean;
rateLimit.perTool?
optional perTool?: Record<string, {
  capacity: number;
  refillIntervalMs: number;
  refillRate: number;
}>;

Per-tool rate limits (Issue #274 Phase 2)

rateLimit.requestsPerMinute
requestsPerMinute: number;
sandbox?
optional sandbox?: {
  dockerImage?: string;
  fallbackToPolicy: boolean;
  mode: "policy" | "none" | "container";
  networkEnabled: boolean;
};

Sandbox execution configuration (Issue #175)

sandbox.dockerImage?
optional dockerImage?: string;

Docker image to use in container mode (default: ‘node:22-alpine’)

sandbox.fallbackToPolicy
fallbackToPolicy: boolean;

Fall back to policy mode if container mode unavailable (default: true)

sandbox.mode
mode: "policy" | "none" | "container";

Sandbox execution mode (default: ‘policy’)

sandbox.networkEnabled
networkEnabled: boolean;

Enable network access in container mode (default: false)

secretsFile?
optional secretsFile?: string;
timeout?
optional timeout?: {
  defaultTimeoutMs: number;
  enableLogging: boolean;
  maxTimeoutMs: number;
  perToolTimeout?: Record<string, number>;
  uriValidation: boolean;
};

Timeout configuration (Issue #271, CVE-2026-0621)

timeout.defaultTimeoutMs
defaultTimeoutMs: number;

Default timeout in milliseconds (default: 30000)

timeout.enableLogging
enableLogging: boolean;

Whether to log timeout events (default: true)

timeout.maxTimeoutMs
maxTimeoutMs: number;

Maximum timeout in milliseconds (default: 300000)

timeout.perToolTimeout?
optional perToolTimeout?: Record<string, number>;

Per-tool timeout overrides in milliseconds (Issue #657)

timeout.uriValidation
uriValidation: boolean;

Enable URI validation to prevent ReDoS (default: true)

toolAllowlist?
optional toolAllowlist?: string[];

Tool allowlist — when set, only listed tools are registered (Issue #740)

Inherited from

BaseMcpToolDeps.security


CreateExpertResponse

Defined in: packages/nexus-agents/src/mcp/tools/create-expert.ts:116

Response from create_expert tool.

Properties

capabilities
capabilities: readonly AgentCapability[];

Defined in: packages/nexus-agents/src/mcp/tools/create-expert.ts:122

List of capabilities

expertId
expertId: string;

Defined in: packages/nexus-agents/src/mcp/tools/create-expert.ts:118

Unique expert ID

role
role: string;

Defined in: packages/nexus-agents/src/mcp/tools/create-expert.ts:120

Expert role

status
status: "ready";

Defined in: packages/nexus-agents/src/mcp/tools/create-expert.ts:124

Expert status


DelegateDeps

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:123

Dependencies for the delegate_to_model tool.

Extends

Properties

feedbackIntegration?
optional feedbackIntegration?: IFeedbackIntegration;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:127

Optional FeedbackIntegration for closed-loop learning (Issue #167)

logger?
optional logger?: ILogger;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:33

Optional logger

Inherited from

BaseMcpToolDeps.logger

notifier?
optional notifier?: IMcpNotifier;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:129

MCP notifier for client-visible logging (Issue #974)

rateLimiter
rateLimiter: McpRateLimiter;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:35

Rate limiter for throttling tool calls (required)

Inherited from

BaseMcpToolDeps.rateLimiter

router?
optional router?: ICompositeRouter;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:125

Optional CompositeRouter for intelligent routing (Issue #169)

security?
optional security?: {
  allowedPaths: string[];
  audit?: {
     enabled: boolean;
     enableHashChain: boolean;
     logDir?: string;
     maxFiles: number;
     maxFileSizeBytes: number;
     minSeverity: "critical" | "info" | "warning";
  };
  auth?: {
     enabled: boolean;
     method: "token" | "oauth2";
     tokenFile?: string;
     tokenHeader: string;
  };
  blockedPatterns: string[];
  policy?: {
     defaultMode: "read-only" | "read-write";
     policyMode: "warn" | "enforce";
  };
  rateLimit: {
     enabled: boolean;
     perTool?: Record<string, {
        capacity: number;
        refillIntervalMs: number;
        refillRate: number;
     }>;
     requestsPerMinute: number;
  };
  sandbox?: {
     dockerImage?: string;
     fallbackToPolicy: boolean;
     mode: "policy" | "none" | "container";
     networkEnabled: boolean;
  };
  secretsFile?: string;
  timeout?: {
     defaultTimeoutMs: number;
     enableLogging: boolean;
     maxTimeoutMs: number;
     perToolTimeout?: Record<string, number>;
     uriValidation: boolean;
  };
  toolAllowlist?: string[];
};

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:37

Security configuration (includes timeout settings)

allowedPaths
allowedPaths: string[];
audit?
optional audit?: {
  enabled: boolean;
  enableHashChain: boolean;
  logDir?: string;
  maxFiles: number;
  maxFileSizeBytes: number;
  minSeverity: "critical" | "info" | "warning";
};

Audit logging configuration (Issue #740 Phase 2).

The block is optional and the inner defaults only apply when it is present: a config with no audit: block is audit-OFF (initializeAuditLogger returns null and startup warns). config init writes the block explicitly so a generated config is on by default (#5632).

audit.enabled
enabled: boolean;

Enable audit logging (default when the block is present: true)

audit.enableHashChain
enableHashChain: boolean;

Enable tamper-evident hash chain (default: true)

audit.logDir?
optional logDir?: string;

Log directory (default: ~/.nexus-agents/audit)

audit.maxFiles
maxFiles: number;

Maximum number of log files to retain (default: 10)

audit.maxFileSizeBytes
maxFileSizeBytes: number;

Maximum log file size in bytes (default: 10MB)

audit.minSeverity
minSeverity: "critical" | "info" | "warning";

Minimum severity to log (default: ‘info’)

auth?
optional auth?: {
  enabled: boolean;
  method: "token" | "oauth2";
  tokenFile?: string;
  tokenHeader: string;
};

Authentication configuration (Issue #739)

auth.enabled
enabled: boolean;

Enable authentication for network-exposed transports (default: true)

auth.method
method: "token" | "oauth2";

Authentication method (default: ‘token’)

auth.tokenFile?
optional tokenFile?: string;

Token file path (default: ~/.nexus-agents/auth/server-token)

auth.tokenHeader
tokenHeader: string;

Header name for bearer token (default: ‘Authorization’)

blockedPatterns
blockedPatterns: string[];
policy?
optional policy?: {
  defaultMode: "read-only" | "read-write";
  policyMode: "warn" | "enforce";
};

Policy firewall configuration

policy.defaultMode
defaultMode: "read-only" | "read-write";

Execution mode for tool operations (default: ‘read-write’; ‘read-only’ is the opt-in lock, #6431)

policy.policyMode
policyMode: "warn" | "enforce";

Policy enforcement mode (default: ‘enforce’)

rateLimit
rateLimit: {
  enabled: boolean;
  perTool?: Record<string, {
     capacity: number;
     refillIntervalMs: number;
     refillRate: number;
  }>;
  requestsPerMinute: number;
};
rateLimit.enabled
enabled: boolean;
rateLimit.perTool?
optional perTool?: Record<string, {
  capacity: number;
  refillIntervalMs: number;
  refillRate: number;
}>;

Per-tool rate limits (Issue #274 Phase 2)

rateLimit.requestsPerMinute
requestsPerMinute: number;
sandbox?
optional sandbox?: {
  dockerImage?: string;
  fallbackToPolicy: boolean;
  mode: "policy" | "none" | "container";
  networkEnabled: boolean;
};

Sandbox execution configuration (Issue #175)

sandbox.dockerImage?
optional dockerImage?: string;

Docker image to use in container mode (default: ‘node:22-alpine’)

sandbox.fallbackToPolicy
fallbackToPolicy: boolean;

Fall back to policy mode if container mode unavailable (default: true)

sandbox.mode
mode: "policy" | "none" | "container";

Sandbox execution mode (default: ‘policy’)

sandbox.networkEnabled
networkEnabled: boolean;

Enable network access in container mode (default: false)

secretsFile?
optional secretsFile?: string;
timeout?
optional timeout?: {
  defaultTimeoutMs: number;
  enableLogging: boolean;
  maxTimeoutMs: number;
  perToolTimeout?: Record<string, number>;
  uriValidation: boolean;
};

Timeout configuration (Issue #271, CVE-2026-0621)

timeout.defaultTimeoutMs
defaultTimeoutMs: number;

Default timeout in milliseconds (default: 30000)

timeout.enableLogging
enableLogging: boolean;

Whether to log timeout events (default: true)

timeout.maxTimeoutMs
maxTimeoutMs: number;

Maximum timeout in milliseconds (default: 300000)

timeout.perToolTimeout?
optional perToolTimeout?: Record<string, number>;

Per-tool timeout overrides in milliseconds (Issue #657)

timeout.uriValidation
uriValidation: boolean;

Enable URI validation to prevent ReDoS (default: true)

toolAllowlist?
optional toolAllowlist?: string[];

Tool allowlist — when set, only listed tools are registered (Issue #740)

Inherited from

BaseMcpToolDeps.security


DryRunResult

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:144

Dry run validation result.

Properties

inputsMissing
inputsMissing: string[];

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:150

inputsProvided
inputsProvided: string[];

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:148

inputsRequired
inputsRequired: string[];

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:149

stepCount
stepCount: number;

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:147

valid
valid: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:145

validationErrors
validationErrors: string[];

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:151

workflowName
workflowName: string;

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:146


EventBusBridgeResult

Defined in: packages/nexus-agents/src/mcp/eventbus-bridge.ts:65

Result of bridge initialization.

Properties

cleanup
readonly cleanup: () => void;

Defined in: packages/nexus-agents/src/mcp/eventbus-bridge.ts:71

Cleanup function to call on shutdown

Returns

void

initialized
readonly initialized: boolean;

Defined in: packages/nexus-agents/src/mcp/eventbus-bridge.ts:67

Whether the bridge was initialized

subscriptionCount
readonly subscriptionCount: number;

Defined in: packages/nexus-agents/src/mcp/eventbus-bridge.ts:69

Number of active subscriptions


ExecuteExpertDeps

Defined in: packages/nexus-agents/src/mcp/tools/execute-expert.ts:105

Dependencies for execute_expert tool.

Extends

Properties

auditLogger?
optional auditLogger?: IAuditLogger;

Defined in: packages/nexus-agents/src/mcp/tools/execute-expert.ts:114

Durable, hash-chained audit logger (#4097). Its only reader was the access-constraint deriver’s ALS audit trail, deleted in #5108; nothing in this tool consumes it today. Kept because ExecuteExpertDeps is published — dropping the member is a breaking change for the next major (#6319).

cliCache?
optional cliCache?: ICliDetectionCache;

Defined in: packages/nexus-agents/src/mcp/tools/execute-expert.ts:116

Optional CLI detection cache for checking available CLIs (Issue #747)

expertRegistry
expertRegistry: Map<string, Expert>;

Defined in: packages/nexus-agents/src/mcp/tools/execute-expert.ts:107

Registry of created experts (shared with create_expert)

logger?
optional logger?: ILogger;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:33

Optional logger

Inherited from

BaseMcpToolDeps.logger

notifier?
optional notifier?: IMcpNotifier;

Defined in: packages/nexus-agents/src/mcp/tools/execute-expert.ts:118

MCP notifier for client-visible logging (Issue #974)

rateLimiter
rateLimiter: McpRateLimiter;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:35

Rate limiter for throttling tool calls (required)

Inherited from

BaseMcpToolDeps.rateLimiter

security?
optional security?: {
  allowedPaths: string[];
  audit?: {
     enabled: boolean;
     enableHashChain: boolean;
     logDir?: string;
     maxFiles: number;
     maxFileSizeBytes: number;
     minSeverity: "critical" | "info" | "warning";
  };
  auth?: {
     enabled: boolean;
     method: "token" | "oauth2";
     tokenFile?: string;
     tokenHeader: string;
  };
  blockedPatterns: string[];
  policy?: {
     defaultMode: "read-only" | "read-write";
     policyMode: "warn" | "enforce";
  };
  rateLimit: {
     enabled: boolean;
     perTool?: Record<string, {
        capacity: number;
        refillIntervalMs: number;
        refillRate: number;
     }>;
     requestsPerMinute: number;
  };
  sandbox?: {
     dockerImage?: string;
     fallbackToPolicy: boolean;
     mode: "policy" | "none" | "container";
     networkEnabled: boolean;
  };
  secretsFile?: string;
  timeout?: {
     defaultTimeoutMs: number;
     enableLogging: boolean;
     maxTimeoutMs: number;
     perToolTimeout?: Record<string, number>;
     uriValidation: boolean;
  };
  toolAllowlist?: string[];
};

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:37

Security configuration (includes timeout settings)

allowedPaths
allowedPaths: string[];
audit?
optional audit?: {
  enabled: boolean;
  enableHashChain: boolean;
  logDir?: string;
  maxFiles: number;
  maxFileSizeBytes: number;
  minSeverity: "critical" | "info" | "warning";
};

Audit logging configuration (Issue #740 Phase 2).

The block is optional and the inner defaults only apply when it is present: a config with no audit: block is audit-OFF (initializeAuditLogger returns null and startup warns). config init writes the block explicitly so a generated config is on by default (#5632).

audit.enabled
enabled: boolean;

Enable audit logging (default when the block is present: true)

audit.enableHashChain
enableHashChain: boolean;

Enable tamper-evident hash chain (default: true)

audit.logDir?
optional logDir?: string;

Log directory (default: ~/.nexus-agents/audit)

audit.maxFiles
maxFiles: number;

Maximum number of log files to retain (default: 10)

audit.maxFileSizeBytes
maxFileSizeBytes: number;

Maximum log file size in bytes (default: 10MB)

audit.minSeverity
minSeverity: "critical" | "info" | "warning";

Minimum severity to log (default: ‘info’)

auth?
optional auth?: {
  enabled: boolean;
  method: "token" | "oauth2";
  tokenFile?: string;
  tokenHeader: string;
};

Authentication configuration (Issue #739)

auth.enabled
enabled: boolean;

Enable authentication for network-exposed transports (default: true)

auth.method
method: "token" | "oauth2";

Authentication method (default: ‘token’)

auth.tokenFile?
optional tokenFile?: string;

Token file path (default: ~/.nexus-agents/auth/server-token)

auth.tokenHeader
tokenHeader: string;

Header name for bearer token (default: ‘Authorization’)

blockedPatterns
blockedPatterns: string[];
policy?
optional policy?: {
  defaultMode: "read-only" | "read-write";
  policyMode: "warn" | "enforce";
};

Policy firewall configuration

policy.defaultMode
defaultMode: "read-only" | "read-write";

Execution mode for tool operations (default: ‘read-write’; ‘read-only’ is the opt-in lock, #6431)

policy.policyMode
policyMode: "warn" | "enforce";

Policy enforcement mode (default: ‘enforce’)

rateLimit
rateLimit: {
  enabled: boolean;
  perTool?: Record<string, {
     capacity: number;
     refillIntervalMs: number;
     refillRate: number;
  }>;
  requestsPerMinute: number;
};
rateLimit.enabled
enabled: boolean;
rateLimit.perTool?
optional perTool?: Record<string, {
  capacity: number;
  refillIntervalMs: number;
  refillRate: number;
}>;

Per-tool rate limits (Issue #274 Phase 2)

rateLimit.requestsPerMinute
requestsPerMinute: number;
sandbox?
optional sandbox?: {
  dockerImage?: string;
  fallbackToPolicy: boolean;
  mode: "policy" | "none" | "container";
  networkEnabled: boolean;
};

Sandbox execution configuration (Issue #175)

sandbox.dockerImage?
optional dockerImage?: string;

Docker image to use in container mode (default: ‘node:22-alpine’)

sandbox.fallbackToPolicy
fallbackToPolicy: boolean;

Fall back to policy mode if container mode unavailable (default: true)

sandbox.mode
mode: "policy" | "none" | "container";

Sandbox execution mode (default: ‘policy’)

sandbox.networkEnabled
networkEnabled: boolean;

Enable network access in container mode (default: false)

secretsFile?
optional secretsFile?: string;
timeout?
optional timeout?: {
  defaultTimeoutMs: number;
  enableLogging: boolean;
  maxTimeoutMs: number;
  perToolTimeout?: Record<string, number>;
  uriValidation: boolean;
};

Timeout configuration (Issue #271, CVE-2026-0621)

timeout.defaultTimeoutMs
defaultTimeoutMs: number;

Default timeout in milliseconds (default: 30000)

timeout.enableLogging
enableLogging: boolean;

Whether to log timeout events (default: true)

timeout.maxTimeoutMs
maxTimeoutMs: number;

Maximum timeout in milliseconds (default: 300000)

timeout.perToolTimeout?
optional perToolTimeout?: Record<string, number>;

Per-tool timeout overrides in milliseconds (Issue #657)

timeout.uriValidation
uriValidation: boolean;

Enable URI validation to prevent ReDoS (default: true)

toolAllowlist?
optional toolAllowlist?: string[];

Tool allowlist — when set, only listed tools are registered (Issue #740)

Inherited from

BaseMcpToolDeps.security


ExecuteExpertResponse

Defined in: packages/nexus-agents/src/mcp/tools/execute-expert.ts:124

Response from execute_expert tool.

Properties

confidence?
optional confidence?: number;

Defined in: packages/nexus-agents/src/mcp/tools/execute-expert.ts:151

The expert’s self-reported confidence in [0, 1] (#3766). Present only when the expert emitted an ExpertOutput-shaped analysis carrying a numeric confidence; absent for plain-string outputs. Consumers can route/weight on it.

durationMs
durationMs: number;

Defined in: packages/nexus-agents/src/mcp/tools/execute-expert.ts:132

Execution duration in milliseconds

error?
optional error?: string;

Defined in: packages/nexus-agents/src/mcp/tools/execute-expert.ts:143

Error message if status is ‘error’

expertId
expertId: string;

Defined in: packages/nexus-agents/src/mcp/tools/execute-expert.ts:126

Expert ID that executed the task

modelUsed?
optional modelUsed?: string;

Defined in: packages/nexus-agents/src/mcp/tools/execute-expert.ts:145

Model used for execution (Issue #817)

output
output: string;

Defined in: packages/nexus-agents/src/mcp/tools/execute-expert.ts:130

Task execution output

role
role: string;

Defined in: packages/nexus-agents/src/mcp/tools/execute-expert.ts:128

Expert role

status
status: "error" | "success";

Defined in: packages/nexus-agents/src/mcp/tools/execute-expert.ts:141

Status of execution

tokensMeasured?
optional tokensMeasured?: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/execute-expert.ts:139

Whether tokensUsed is measured. false means the adapter reported no usage, so tokensUsed is a placeholder zero rather than a measurement.

tokensUsed
tokensUsed: number;

Defined in: packages/nexus-agents/src/mcp/tools/execute-expert.ts:134

Token usage from the model


ExpertInfo

Defined in: packages/nexus-agents/src/mcp/tools/list-experts.ts:51

Expert information returned by list_experts tool.

Properties

capabilities
capabilities: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/list-experts.ts:59

List of capabilities

description
description: string;

Defined in: packages/nexus-agents/src/mcp/tools/list-experts.ts:57

Expert description

name
name: string;

Defined in: packages/nexus-agents/src/mcp/tools/list-experts.ts:55

Human-readable name

role
role: string;

Defined in: packages/nexus-agents/src/mcp/tools/list-experts.ts:53

Role identifier for create_expert


FiledIssue

Defined in: packages/nexus-agents/src/mcp/tools/improvement-review-issue-filing.ts:49

One filed issue plus what happened to its requested labels (#6112).

Properties

issueUrl
readonly issueUrl: string;

Defined in: packages/nexus-agents/src/mcp/tools/improvement-review-issue-filing.ts:51

labelCheck
readonly labelCheck: "ok" | "truncated" | "unavailable";

Defined in: packages/nexus-agents/src/mcp/tools/improvement-review-issue-filing.ts:63

ok — gh label list answered and the filter above is real; unavailable — the list failed, so the issue was filed with NO labels and every requested label is in labelsDropped; truncated — the list filled its page (LABEL_LIST_LIMIT), so a label past it cannot be told from a missing one: no filtering was done, every requested label was passed and labelsDropped is []. The lookup never blocks the signal.

labelsDropped
readonly labelsDropped: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/improvement-review-issue-filing.ts:53

Requested labels the target repo does not have; explicit [] when none.

signalKey
readonly signalKey: string;

Defined in: packages/nexus-agents/src/mcp/tools/improvement-review-issue-filing.ts:50


FirewallArtifact

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:22

Artifact type for policy context. Artifacts are resources that can be referenced in policy decisions.

Type Parameters

T

T = unknown

Properties

createdAt
readonly createdAt: Date;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:26

id
readonly id: string;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:23

type
readonly type: string;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:24

value
readonly value: T;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:25


FirewallPolicyContext

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:72

Context provided to policy rules for evaluation.

Properties

allowedPaths?
readonly optional allowedPaths?: readonly string[];

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:78

args
readonly args: unknown;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:74

artifacts?
readonly optional artifacts?: Map<string, FirewallArtifact<unknown>>;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:76

mode
readonly mode: ExecutionMode;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:75

toolName
readonly toolName: string;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:73

workflowId?
readonly optional workflowId?: string;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:77


FirewallPolicyDecision

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:47

Result of a policy evaluation.

Properties

allowed
readonly allowed: boolean;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:48

overriddenByWarnMode?
readonly optional overriddenByWarnMode?: boolean;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:66

A rule denied this call and warn mode overrode the denial, so allowed is true but the operation WOULD have been blocked in enforce mode (#4991).

Set explicitly by the evaluator rather than inferred downstream. The first implementation deduced it from allowed === true && ruleName !== undefined — true of today’s code, because allowWithReason never sets ruleName — and a consensus panel rejected that: naming which rule permitted an action (admin-override vs default-allow) is ordinary access-control practice, so the day an allow rule sets ruleName, every authorized call it covers would be silently recorded as a near-miss. Deriving a verdict from the absence of an unrelated field is not a signal, it is a coincidence.

reason
readonly reason: string;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:49

requiredArtifact?
readonly optional requiredArtifact?: string;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:50

ruleName?
readonly optional ruleName?: string;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:51


FirewallPolicyRule

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:84

A single policy rule that can approve or deny operations.

Properties

description
readonly description: string;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:86

name
readonly name: string;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:85

Methods

check()
check(ctx): FirewallPolicyDecision;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:87

Parameters
ctx

FirewallPolicyContext

Returns

FirewallPolicyDecision


GetJobResultResponse

Defined in: packages/nexus-agents/src/mcp/tools/get-job-result-tool.ts:51

Response envelope. found: false means the jobId is unknown (or the sidecar file is unreadable / future-schema). found: true carries the full record — caller branches on record.status.

Properties

abandoned?
readonly optional abandoned?: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/get-job-result-tool.ts:63

Set when a pending record has outlived the runaway guard that bounds every job body (#4976), so no live process can still be working on it.

The record itself is left saying pending — it is evidence of what was observed, and rewriting it on read would destroy that. This field is the qualifier a poller needs to stop waiting.

errorMessage?
readonly optional errorMessage?: string;

Defined in: packages/nexus-agents/src/mcp/tools/get-job-result-tool.ts:82

found
readonly found: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/get-job-result-tool.ts:53

jobId
readonly jobId: string;

Defined in: packages/nexus-agents/src/mcp/tools/get-job-result-tool.ts:52

producerVersionMeasured?
readonly optional producerVersionMeasured?: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/get-job-result-tool.ts:73

Whether record.producerVersion identifies a build (#5008). Present whenever found is true.

This tool’s own _meta['nexus-agents/build'] stamp names the READER’s build; record.producerVersion names the build that ran the job. false when the record predates the field or the producer was a 'dev' build, in which case the two stamps must not be compared.

producerVersionSource?
readonly optional producerVersionSource?: JobResultSource;

Defined in: packages/nexus-agents/src/mcp/tools/get-job-result-tool.ts:81

Which store the record came from (#5008 follow-up). Present whenever found is true. A task_state record is synthesized from the task-state log and never carries producerVersion, so on that source an absent version says nothing about the producer’s age or build — only a sidecar record’s absence means it predates the field.

record?
readonly optional record?: {
  cancelledPartial?: {
     panelSize: number;
     partialVotes: unknown[];
     seatsCast: number;
  };
  completedAt?: string;
  createdAt: string;
  error?: string;
  errorKind?: "abandoned";
  failureDetail?: {
     adapter: string;
     category: string;
     transport: string;
  };
  jobId: string;
  lastProgressAt?: string;
  producerVersion?: string;
  result?: unknown;
  signalAccepted?: boolean;
  status: "failed" | "cancelled" | "pending" | "complete";
  toolName: string;
  v: 1;
};

Defined in: packages/nexus-agents/src/mcp/tools/get-job-result-tool.ts:54

cancelledPartial?
optional cancelledPartial?: {
  panelSize: number;
  partialVotes: unknown[];
  seatsCast: number;
};

What a cancelled vote had collected when cancel_job fired (#6735). Present only on a cancelled record, and only when the body settled after the cancel and reported what it had. Written only by attachCancelledPartial (job-cancelled-partial.ts), never by a status transition.

cancelledPartial.panelSize
panelSize: number;
cancelledPartial.partialVotes
partialVotes: unknown[];
cancelledPartial.seatsCast
seatsCast: number;
completedAt?
optional completedAt?: string;

Set when the job leaves pending — either via complete or failed or cancelled.

createdAt
createdAt: string;
error?
optional error?: string;

Failure message when status === 'failed'. Cannot be paired with result — the discriminator is status.

errorKind?
optional errorKind?: "abandoned";

Machine-readable reason for a failed record that was NOT settled by the process that ran the job (#6224). abandoned is written only by pruneJobRecords: the record was pending past the runaway guard (so no live process could still own it) AND past the retention window, and the sweep rewrote it rather than deleting it. Absent on every record the job’s own process wrote — error alone carries those failures.

failureDetail?
optional failureDetail?: {
  adapter: string;
  category: string;
  transport: string;
};

Structured failure detail when status === 'failed' (#4375). Holds normalized adapter, transport, and category information without raw response bodies or prompt strings.

failureDetail.adapter
adapter: string;

Identifier of the failing adapter (e.g. ‘claude’, ‘codex’, ‘api:anthropic’).

failureDetail.category
category: string;

Normalized failure category (e.g. ‘rate_limited’, ‘timeout’, ‘capacity_exhausted’).

failureDetail.transport
transport: string;

Transport mechanism where the failure occurred (e.g. ‘subprocess’, ‘mcp’, ‘stdio’).

jobId
jobId: string;
lastProgressAt?
optional lastProgressAt?: string;

When the job body last heartbeat — runAsJob’s progress() callback, heartbeatJob, or a pipeline-bus event the body emitted (#6162). Present once the body has heartbeat at least once and carried onto the terminal record, so a settled job still says when it last moved (a wedged failed record: the last progress before the silence). Absence means “no heartbeat recorded”, never “no progress” — a body that predates the callback, or one that never adopted it, leaves the field off. On a long guard the reaper in run-as-job.ts fails a body that stops heartbeating as wedged, measuring silence from this stamp (or from job start when there is none).

producerVersion?
optional producerVersion?: string;

VERSION of the nexus-agents process that WROTE this record (#5008) — i.e. the build that ran the job, not the build that reads it back.

get_job_result is itself a wrapped tool, so its _meta['nexus-agents/build'] stamp (#5056) names the READER’s build. After a mid-session global install the reader and the producer differ, and only the record can say which build produced the payload. Each writer re-stamps on its own transition, so a terminal record names the process that settled it.

Optional so v1 records written before this field existed still parse: on a SIDECAR record, absence means “produced before this field existed”, not a version of undefined. A record adapted from the task-state log (jobResultFromTaskState, selected by NEXUS_JOB_RESULT_SOURCE=task_state) NEVER carries it — that log records no producer version — so a reader must consult the source (get_job_result’s producerVersionSource) before reading absence as age. The value is recorded verbatim, including 'dev' — readers MUST run it through isMeasuredBuildVersion before treating two stamps as comparable.

result?
optional result?: unknown;

Structured payload the synchronous mode would have returned. Present only when status === 'complete'. Shape is tool-specific — readers cast to the tool’s known output type after status check.

signalAccepted?
optional signalAccepted?: boolean;

Whether the tool’s run callback accepts runAsJob’s AbortSignal (#4972).

cancel_job writes a cancelled record whether or not the tool can act on the signal — as cancel-job-tool.ts says, “a tool that IGNORES the signal still runs to completion… but its record stays cancelled”. A reader of that record could not tell the two apart, so cancelled claimed more than was known.

This is a STRUCTURAL fact — the callback’s arity — not a behavioural one. A tool may accept the signal and never await on it, so true means “cancellation can reach this tool”, not “the work stopped”. Absent means the writer did not report it, which is not the same as false.

status
status: "failed" | "cancelled" | "pending" | "complete" = JobStatusSchema;
toolName
toolName: string;

Tool that was invoked (e.g. orchestrate).

v
v: 1;

Format version. Currently 1 — bump if the shape changes.


GraphWorkflowInfo

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow-templates.ts:40

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports

Properties

description
readonly description: string;

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow-templates.ts:42

hasConditionalEdges
readonly hasConditionalEdges: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow-templates.ts:45

inputFields
readonly inputFields: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow-templates.ts:43

name
readonly name: string;

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow-templates.ts:41

nodeCount
readonly nodeCount: number;

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow-templates.ts:44


IMcpNotifier

Defined in: packages/nexus-agents/src/mcp/mcp-notifier.ts:30

MCP notifier for sending structured log events to clients.

Methods

debug()
debug(logger, data): void;

Defined in: packages/nexus-agents/src/mcp/mcp-notifier.ts:34

Send debug-level notification (detailed execution steps)

Parameters
logger

string

data

Record<string, unknown>

Returns

void

info()
info(logger, data): void;

Defined in: packages/nexus-agents/src/mcp/mcp-notifier.ts:32

Send info-level notification (key orchestration events)

Parameters
logger

string

data

Record<string, unknown>

Returns

void

warn()
warn(logger, data): void;

Defined in: packages/nexus-agents/src/mcp/mcp-notifier.ts:36

Send warning-level notification

Parameters
logger

string

data

Record<string, unknown>

Returns

void


ImprovementReviewResponse

Defined in: packages/nexus-agents/src/mcp/tools/improvement-review.ts:166

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports

Properties

issuesFiled
readonly issuesFiled: readonly FiledIssue[];

Defined in: packages/nexus-agents/src/mcp/tools/improvement-review.ts:177

Filed issues, each with the labels the target repo lacked (#6112).

issuesSkipped
readonly issuesSkipped: readonly {
  reason: string;
  signalKey: string;
}[];

Defined in: packages/nexus-agents/src/mcp/tools/improvement-review.ts:178

issueTarget
readonly issueTarget: IssueTarget;

Defined in: packages/nexus-agents/src/mcp/tools/improvement-review.ts:180

Where the issues went and how the target was chosen; not-filing when fileIssues=false.

remediationTasks
readonly remediationTasks: readonly PipelineTask[];

Defined in: packages/nexus-agents/src/mcp/tools/improvement-review.ts:175

Remediation tasks derived from signals (#3540 capability-loop increment 1) — SUGGEST-ONLY: structured tasks for a reviewer to consider routing through the dev-pipeline. Nothing here is executed or auto-invoked.

signals
readonly signals: readonly ImprovementSignal[];

Defined in: packages/nexus-agents/src/mcp/tools/improvement-review.ts:169

totalOutcomes
readonly totalOutcomes: number;

Defined in: packages/nexus-agents/src/mcp/tools/improvement-review.ts:168

window
readonly window: string;

Defined in: packages/nexus-agents/src/mcp/tools/improvement-review.ts:167


IPolicyFirewall

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:93

Interface for the policy firewall.

Methods

addRule()
addRule(rule): void;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:95

Parameters
rule

FirewallPolicyRule

Returns

void

evaluate()
evaluate(ctx): FirewallPolicyDecision;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:94

Parameters
ctx

FirewallPolicyContext

Returns

FirewallPolicyDecision

getMode()
getMode(): PolicyMode;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:99

Returns

PolicyMode

getRules()
getRules(): readonly FirewallPolicyRule[];

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:97

Returns

readonly FirewallPolicyRule[]

removeRule()
removeRule(name): boolean;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:96

Parameters
name

string

Returns

boolean

setMode()
setMode(mode): void;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:98

Parameters
mode

PolicyMode

Returns

void


IssueTarget

Defined in: packages/nexus-agents/src/mcp/tools/improvement-review-issue-filing.ts:36

Where the filed issues went, and how that target was chosen (#6112).

Properties

repo
readonly repo: string | null;

Defined in: packages/nexus-agents/src/mcp/tools/improvement-review-issue-filing.ts:38

owner/repo, or null when neither the caller nor the cwd remote named one.

source
readonly source: "input" | "unresolved" | "cwd-remote" | "not-filing";

Defined in: packages/nexus-agents/src/mcp/tools/improvement-review-issue-filing.ts:45

input — the caller passed targetRepo; cwd-remote — resolved via gh repo view from the working directory; unresolved — the lookup failed, so gh was left to its own cwd resolution (no --repo flag); not-filing — fileIssues was false, nothing was resolved.


IssueTriageResponse

Defined in: packages/nexus-agents/src/mcp/tools/issue-triage-tool.ts:58

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports

Properties

category
readonly category: string;

Defined in: packages/nexus-agents/src/mcp/tools/issue-triage-tool.ts:61

categoryConfidence
readonly categoryConfidence: number;

Defined in: packages/nexus-agents/src/mcp/tools/issue-triage-tool.ts:62

durationMs
readonly durationMs: number;

Defined in: packages/nexus-agents/src/mcp/tools/issue-triage-tool.ts:82

issueNumber
readonly issueNumber: number;

Defined in: packages/nexus-agents/src/mcp/tools/issue-triage-tool.ts:59

proposedActions
readonly proposedActions: readonly {
  corroborated: boolean;
  description: string;
  missingCorroboration?: readonly string[];
  policyApproved: boolean;
  policyViolations?: readonly string[];
  refusedAtStage?: "corroboration";
  type: string;
}[];

Defined in: packages/nexus-agents/src/mcp/tools/issue-triage-tool.ts:70

repository
readonly repository: string;

Defined in: packages/nexus-agents/src/mcp/tools/issue-triage-tool.ts:60

trustAssessment
readonly trustAssessment: {
  isSuspicious: boolean;
  reputationScore?: number;
  suspiciousSignals: readonly string[];
  trustTier: string;
  userRole: string;
};

Defined in: packages/nexus-agents/src/mcp/tools/issue-triage-tool.ts:63

isSuspicious
readonly isSuspicious: boolean;
reputationScore?
readonly optional reputationScore?: number;
suspiciousSignals
readonly suspiciousSignals: readonly string[];
trustTier
readonly trustTier: string;
userRole
readonly userRole: string;

LanguageMatrixEntry

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:36

Language matrix: category → scanner names.

Properties

container?
readonly optional container?: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:40

dast?
readonly optional dast?: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:42

iac?
readonly optional iac?: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:41

sast?
readonly optional sast?: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:37

sca?
readonly optional sca?: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:38

secrets?
readonly optional secrets?: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:39


ListExpertsResponse

Defined in: packages/nexus-agents/src/mcp/tools/list-experts.ts:65

Response from list_experts tool.

Properties

count
count: number;

Defined in: packages/nexus-agents/src/mcp/tools/list-experts.ts:69

Total count

experts
experts: ExpertInfo[];

Defined in: packages/nexus-agents/src/mcp/tools/list-experts.ts:67

List of available experts


ListJobsResponse

Defined in: packages/nexus-agents/src/mcp/tools/list-jobs-tool.ts:93

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports

Properties

count
readonly count: number;

Defined in: packages/nexus-agents/src/mcp/tools/list-jobs-tool.ts:94

jobs
readonly jobs: readonly JobSummary[];

Defined in: packages/nexus-agents/src/mcp/tools/list-jobs-tool.ts:102

jobsDirUnreadable?
readonly optional jobsDirUnreadable?: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/list-jobs-tool.ts:104

Present only when the jobs directory exists but could not be enumerated.

truncated
readonly truncated: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/list-jobs-tool.ts:101

Whether the LIMIT CAP dropped entries. Deliberately narrow: it says nothing about whether the underlying read was complete, which is what ListJobsResponse.jobsDirUnreadable and ListJobsResponse.unparseableRecords are for (#6038).

unparseableRecords?
readonly optional unparseableRecords?: number;

Defined in: packages/nexus-agents/src/mcp/tools/list-jobs-tool.ts:106

Present only when sidecar files were found but failed to parse or validate.


ListWorkflowsDeps

Defined in: packages/nexus-agents/src/mcp/tools/list-workflows.ts:48

Dependencies for list_workflows tool.

Extends

Properties

logger?
optional logger?: ILogger;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:33

Optional logger

Inherited from

BaseMcpToolDeps.logger

rateLimiter
rateLimiter: McpRateLimiter;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:35

Rate limiter for throttling tool calls (required)

Inherited from

BaseMcpToolDeps.rateLimiter

security?
optional security?: {
  allowedPaths: string[];
  audit?: {
     enabled: boolean;
     enableHashChain: boolean;
     logDir?: string;
     maxFiles: number;
     maxFileSizeBytes: number;
     minSeverity: "critical" | "info" | "warning";
  };
  auth?: {
     enabled: boolean;
     method: "token" | "oauth2";
     tokenFile?: string;
     tokenHeader: string;
  };
  blockedPatterns: string[];
  policy?: {
     defaultMode: "read-only" | "read-write";
     policyMode: "warn" | "enforce";
  };
  rateLimit: {
     enabled: boolean;
     perTool?: Record<string, {
        capacity: number;
        refillIntervalMs: number;
        refillRate: number;
     }>;
     requestsPerMinute: number;
  };
  sandbox?: {
     dockerImage?: string;
     fallbackToPolicy: boolean;
     mode: "policy" | "none" | "container";
     networkEnabled: boolean;
  };
  secretsFile?: string;
  timeout?: {
     defaultTimeoutMs: number;
     enableLogging: boolean;
     maxTimeoutMs: number;
     perToolTimeout?: Record<string, number>;
     uriValidation: boolean;
  };
  toolAllowlist?: string[];
};

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:37

Security configuration (includes timeout settings)

allowedPaths
allowedPaths: string[];
audit?
optional audit?: {
  enabled: boolean;
  enableHashChain: boolean;
  logDir?: string;
  maxFiles: number;
  maxFileSizeBytes: number;
  minSeverity: "critical" | "info" | "warning";
};

Audit logging configuration (Issue #740 Phase 2).

The block is optional and the inner defaults only apply when it is present: a config with no audit: block is audit-OFF (initializeAuditLogger returns null and startup warns). config init writes the block explicitly so a generated config is on by default (#5632).

audit.enabled
enabled: boolean;

Enable audit logging (default when the block is present: true)

audit.enableHashChain
enableHashChain: boolean;

Enable tamper-evident hash chain (default: true)

audit.logDir?
optional logDir?: string;

Log directory (default: ~/.nexus-agents/audit)

audit.maxFiles
maxFiles: number;

Maximum number of log files to retain (default: 10)

audit.maxFileSizeBytes
maxFileSizeBytes: number;

Maximum log file size in bytes (default: 10MB)

audit.minSeverity
minSeverity: "critical" | "info" | "warning";

Minimum severity to log (default: ‘info’)

auth?
optional auth?: {
  enabled: boolean;
  method: "token" | "oauth2";
  tokenFile?: string;
  tokenHeader: string;
};

Authentication configuration (Issue #739)

auth.enabled
enabled: boolean;

Enable authentication for network-exposed transports (default: true)

auth.method
method: "token" | "oauth2";

Authentication method (default: ‘token’)

auth.tokenFile?
optional tokenFile?: string;

Token file path (default: ~/.nexus-agents/auth/server-token)

auth.tokenHeader
tokenHeader: string;

Header name for bearer token (default: ‘Authorization’)

blockedPatterns
blockedPatterns: string[];
policy?
optional policy?: {
  defaultMode: "read-only" | "read-write";
  policyMode: "warn" | "enforce";
};

Policy firewall configuration

policy.defaultMode
defaultMode: "read-only" | "read-write";

Execution mode for tool operations (default: ‘read-write’; ‘read-only’ is the opt-in lock, #6431)

policy.policyMode
policyMode: "warn" | "enforce";

Policy enforcement mode (default: ‘enforce’)

rateLimit
rateLimit: {
  enabled: boolean;
  perTool?: Record<string, {
     capacity: number;
     refillIntervalMs: number;
     refillRate: number;
  }>;
  requestsPerMinute: number;
};
rateLimit.enabled
enabled: boolean;
rateLimit.perTool?
optional perTool?: Record<string, {
  capacity: number;
  refillIntervalMs: number;
  refillRate: number;
}>;

Per-tool rate limits (Issue #274 Phase 2)

rateLimit.requestsPerMinute
requestsPerMinute: number;
sandbox?
optional sandbox?: {
  dockerImage?: string;
  fallbackToPolicy: boolean;
  mode: "policy" | "none" | "container";
  networkEnabled: boolean;
};

Sandbox execution configuration (Issue #175)

sandbox.dockerImage?
optional dockerImage?: string;

Docker image to use in container mode (default: ‘node:22-alpine’)

sandbox.fallbackToPolicy
fallbackToPolicy: boolean;

Fall back to policy mode if container mode unavailable (default: true)

sandbox.mode
mode: "policy" | "none" | "container";

Sandbox execution mode (default: ‘policy’)

sandbox.networkEnabled
networkEnabled: boolean;

Enable network access in container mode (default: false)

secretsFile?
optional secretsFile?: string;
timeout?
optional timeout?: {
  defaultTimeoutMs: number;
  enableLogging: boolean;
  maxTimeoutMs: number;
  perToolTimeout?: Record<string, number>;
  uriValidation: boolean;
};

Timeout configuration (Issue #271, CVE-2026-0621)

timeout.defaultTimeoutMs
defaultTimeoutMs: number;

Default timeout in milliseconds (default: 30000)

timeout.enableLogging
enableLogging: boolean;

Whether to log timeout events (default: true)

timeout.maxTimeoutMs
maxTimeoutMs: number;

Maximum timeout in milliseconds (default: 300000)

timeout.perToolTimeout?
optional perToolTimeout?: Record<string, number>;

Per-tool timeout overrides in milliseconds (Issue #657)

timeout.uriValidation
uriValidation: boolean;

Enable URI validation to prevent ReDoS (default: true)

toolAllowlist?
optional toolAllowlist?: string[];

Tool allowlist — when set, only listed tools are registered (Issue #740)

Inherited from

BaseMcpToolDeps.security

workflowEngine
workflowEngine: IWorkflowEngine;

Defined in: packages/nexus-agents/src/mcp/tools/list-workflows.ts:50

Workflow engine for listing templates


ListWorkflowsResponse

Defined in: packages/nexus-agents/src/mcp/tools/list-workflows.ts:70

Response from list_workflows tool.

Properties

categories?
optional categories?: string[];

Defined in: packages/nexus-agents/src/mcp/tools/list-workflows.ts:76

Categories found (for filtering hints)

count
count: number;

Defined in: packages/nexus-agents/src/mcp/tools/list-workflows.ts:74

Total count

workflows
workflows: WorkflowInfo[];

Defined in: packages/nexus-agents/src/mcp/tools/list-workflows.ts:72

List of available workflows


McpExpertFactory

Defined in: packages/nexus-agents/src/mcp/tools/create-expert.ts:92

Expert factory interface for dependency injection.

Methods

createBuiltIn()
createBuiltIn(type, options?): 
  | {
  ok: true;
  value: Expert;
}
  | {
  error: Error;
  ok: false;
};

Defined in: packages/nexus-agents/src/mcp/tools/create-expert.ts:93

Parameters
type

BuiltInExpertType

options?
modelOverrides?

{ modelId?: string; }

modelOverrides.modelId?

string

recoveryPolicy?

ExpertRecoveryPolicy

Returns

| { ok: true; value: Expert; } | { error: Error; ok: false; }


McpLogContext

Defined in: packages/nexus-agents/src/mcp/middleware/logging.ts:13

MCP-specific log context fields.

Extends

Indexable

[key: string]: unknown

Properties

durationMs?
optional durationMs?: number;

Defined in: packages/nexus-agents/src/mcp/middleware/logging.ts:19

Duration of the operation in milliseconds

errorCode?
optional errorCode?: string;

Defined in: packages/nexus-agents/src/mcp/middleware/logging.ts:23

Error code if operation failed

requestId?
optional requestId?: string;

Defined in: packages/nexus-agents/src/mcp/middleware/logging.ts:17

Request ID for tracing

success?
optional success?: boolean;

Defined in: packages/nexus-agents/src/mcp/middleware/logging.ts:21

Whether the operation succeeded

tool?
optional tool?: string;

Defined in: packages/nexus-agents/src/mcp/middleware/logging.ts:15

The tool being executed


McpRateLimiterConfig

Defined in: packages/nexus-agents/src/mcp/middleware/rate-limiter.ts:15

Configuration for the token bucket rate limiter.

Properties

capacity
readonly capacity: number;

Defined in: packages/nexus-agents/src/mcp/middleware/rate-limiter.ts:17

Maximum number of tokens in the bucket

logger?
readonly optional logger?: ILogger;

Defined in: packages/nexus-agents/src/mcp/middleware/rate-limiter.ts:23

Optional logger instance

name?
readonly optional name?: string;

Defined in: packages/nexus-agents/src/mcp/middleware/rate-limiter.ts:25

Optional identifier for logging

refillIntervalMs?
readonly optional refillIntervalMs?: number;

Defined in: packages/nexus-agents/src/mcp/middleware/rate-limiter.ts:21

Interval in milliseconds between token refills (default: 1000ms)

refillRate
readonly refillRate: number;

Defined in: packages/nexus-agents/src/mcp/middleware/rate-limiter.ts:19

Number of tokens added per interval


MemoryQueryResponse

Defined in: packages/nexus-agents/src/mcp/tools/memory-query.ts:73

Response from memory_query tool.

Properties

count
count: number;

Defined in: packages/nexus-agents/src/mcp/tools/memory-query.ts:81

Total results returned

errored
errored: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/memory-query.ts:102

Backends that were installed and threw while answering (#4999).

Distinct from unavailable: the store is here, it just could not answer. Each helper swallows its own failure into an empty result set, so without this a corrupted SQLite file read exactly like a store with no matches.

expandedQuery?
optional expandedQuery?: string;

Defined in: packages/nexus-agents/src/mcp/tools/memory-query.ts:77

LLM-expanded query when reflective memory rewrites it (Issue #1397 Gap 1).

query
query: string;

Defined in: packages/nexus-agents/src/mcp/tools/memory-query.ts:75

Query that was executed

results
results: readonly UnifiedMemoryResult[];

Defined in: packages/nexus-agents/src/mcp/tools/memory-query.ts:79

Results from memory search

searched
searched: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/memory-query.ts:92

Which backends the search could actually reach (#4999).

count: 0 used to be the same observation whether nothing matched or the SQLite-backed stores were absent — every unavailable backend contributes [] silently. A caller asking “do we know anything about X?” was told “no” when the honest answer was “two of the four stores were not there”.

source
source: string;

Defined in: packages/nexus-agents/src/mcp/tools/memory-query.ts:83

Source filter applied

unavailable
unavailable: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/memory-query.ts:94

Backends skipped because they are not configured on this install.


MemoryStatsResponse

Defined in: packages/nexus-agents/src/mcp/tools/memory-stats.ts:102

Response from memory_stats tool.

Properties

backends
backends: BackendStatus;

Defined in: packages/nexus-agents/src/mcp/tools/memory-stats.ts:104

Backend availability status

belief
belief: BeliefStats;

Defined in: packages/nexus-agents/src/mcp/tools/memory-stats.ts:108

Belief memory stats

collectedAt
collectedAt: string;

Defined in: packages/nexus-agents/src/mcp/tools/memory-stats.ts:121

Timestamp of stats collection

decay
decay: Record<string, unknown> | null;

Defined in: packages/nexus-agents/src/mcp/tools/memory-stats.ts:114

Decay stats (if available and requested)

mobimem
mobimem: Record<string, unknown> | null;

Defined in: packages/nexus-agents/src/mcp/tools/memory-stats.ts:112

MobiMem stats (if available)

registry
registry: readonly RegistryDomainStats[];

Defined in: packages/nexus-agents/src/mcp/tools/memory-stats.ts:119

Per-domain stats from the unified MemoryRegistry (Phase 5 of #2766). One entry per attached backend; empty when no backend has registered.

session
session: SessionStats;

Defined in: packages/nexus-agents/src/mcp/tools/memory-stats.ts:106

Session memory stats

typed
typed: Record<string, unknown> | null;

Defined in: packages/nexus-agents/src/mcp/tools/memory-stats.ts:110

Typed memory stats (if available)


MemoryWriteResponse

Defined in: packages/nexus-agents/src/mcp/tools/memory-write.ts:83

Response from memory_write tool.

Properties

backend
backend: string;

Defined in: packages/nexus-agents/src/mcp/tools/memory-write.ts:87

Target backend

deduplicated?
optional deduplicated?: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/memory-write.ts:91

Whether write was skipped due to identical content already existing (#1455)

error?
optional error?: string;

Defined in: packages/nexus-agents/src/mcp/tools/memory-write.ts:93

Error message if write failed

key
key: string;

Defined in: packages/nexus-agents/src/mcp/tools/memory-write.ts:89

Key/subject written

success
success: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/memory-write.ts:85

Whether the write succeeded


OrchestrateDeps

Defined in: packages/nexus-agents/src/mcp/tools/orchestrate-types.ts:188

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports

Extends

Properties

auditLogger?
optional auditLogger?: IAuditLogger;

Defined in: packages/nexus-agents/src/mcp/tools/orchestrate-types.ts:202

Durable, hash-chained audit logger (#4097). Its only reader was the access-constraint deriver’s ALS audit trail, deleted in #5108; nothing in the orchestrate tool consumes it today. Kept because OrchestrateDeps is published — dropping the member is a breaking change for the next major (#6319).

logger?
optional logger?: ILogger;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:33

Optional logger

Inherited from

BaseMcpToolDeps.logger

modelAdapter?
optional modelAdapter?: IModelAdapter;

Defined in: packages/nexus-agents/src/mcp/tools/orchestrate-types.ts:192

Model adapter for fallback orchestration path (Issue #827)

notifier?
optional notifier?: IMcpNotifier;

Defined in: packages/nexus-agents/src/mcp/tools/orchestrate-types.ts:194

MCP notifier for client-visible logging (Issue #974)

orchestrator?
optional orchestrator?: IOrchestrator;

Defined in: packages/nexus-agents/src/mcp/tools/orchestrate-types.ts:190

Pre-configured orchestrator instance (unified interface).

rateLimiter
rateLimiter: McpRateLimiter;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:35

Rate limiter for throttling tool calls (required)

Inherited from

BaseMcpToolDeps.rateLimiter

security?
optional security?: {
  allowedPaths: string[];
  audit?: {
     enabled: boolean;
     enableHashChain: boolean;
     logDir?: string;
     maxFiles: number;
     maxFileSizeBytes: number;
     minSeverity: "critical" | "info" | "warning";
  };
  auth?: {
     enabled: boolean;
     method: "token" | "oauth2";
     tokenFile?: string;
     tokenHeader: string;
  };
  blockedPatterns: string[];
  policy?: {
     defaultMode: "read-only" | "read-write";
     policyMode: "warn" | "enforce";
  };
  rateLimit: {
     enabled: boolean;
     perTool?: Record<string, {
        capacity: number;
        refillIntervalMs: number;
        refillRate: number;
     }>;
     requestsPerMinute: number;
  };
  sandbox?: {
     dockerImage?: string;
     fallbackToPolicy: boolean;
     mode: "policy" | "none" | "container";
     networkEnabled: boolean;
  };
  secretsFile?: string;
  timeout?: {
     defaultTimeoutMs: number;
     enableLogging: boolean;
     maxTimeoutMs: number;
     perToolTimeout?: Record<string, number>;
     uriValidation: boolean;
  };
  toolAllowlist?: string[];
};

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:37

Security configuration (includes timeout settings)

allowedPaths
allowedPaths: string[];
audit?
optional audit?: {
  enabled: boolean;
  enableHashChain: boolean;
  logDir?: string;
  maxFiles: number;
  maxFileSizeBytes: number;
  minSeverity: "critical" | "info" | "warning";
};

Audit logging configuration (Issue #740 Phase 2).

The block is optional and the inner defaults only apply when it is present: a config with no audit: block is audit-OFF (initializeAuditLogger returns null and startup warns). config init writes the block explicitly so a generated config is on by default (#5632).

audit.enabled
enabled: boolean;

Enable audit logging (default when the block is present: true)

audit.enableHashChain
enableHashChain: boolean;

Enable tamper-evident hash chain (default: true)

audit.logDir?
optional logDir?: string;

Log directory (default: ~/.nexus-agents/audit)

audit.maxFiles
maxFiles: number;

Maximum number of log files to retain (default: 10)

audit.maxFileSizeBytes
maxFileSizeBytes: number;

Maximum log file size in bytes (default: 10MB)

audit.minSeverity
minSeverity: "critical" | "info" | "warning";

Minimum severity to log (default: ‘info’)

auth?
optional auth?: {
  enabled: boolean;
  method: "token" | "oauth2";
  tokenFile?: string;
  tokenHeader: string;
};

Authentication configuration (Issue #739)

auth.enabled
enabled: boolean;

Enable authentication for network-exposed transports (default: true)

auth.method
method: "token" | "oauth2";

Authentication method (default: ‘token’)

auth.tokenFile?
optional tokenFile?: string;

Token file path (default: ~/.nexus-agents/auth/server-token)

auth.tokenHeader
tokenHeader: string;

Header name for bearer token (default: ‘Authorization’)

blockedPatterns
blockedPatterns: string[];
policy?
optional policy?: {
  defaultMode: "read-only" | "read-write";
  policyMode: "warn" | "enforce";
};

Policy firewall configuration

policy.defaultMode
defaultMode: "read-only" | "read-write";

Execution mode for tool operations (default: ‘read-write’; ‘read-only’ is the opt-in lock, #6431)

policy.policyMode
policyMode: "warn" | "enforce";

Policy enforcement mode (default: ‘enforce’)

rateLimit
rateLimit: {
  enabled: boolean;
  perTool?: Record<string, {
     capacity: number;
     refillIntervalMs: number;
     refillRate: number;
  }>;
  requestsPerMinute: number;
};
rateLimit.enabled
enabled: boolean;
rateLimit.perTool?
optional perTool?: Record<string, {
  capacity: number;
  refillIntervalMs: number;
  refillRate: number;
}>;

Per-tool rate limits (Issue #274 Phase 2)

rateLimit.requestsPerMinute
requestsPerMinute: number;
sandbox?
optional sandbox?: {
  dockerImage?: string;
  fallbackToPolicy: boolean;
  mode: "policy" | "none" | "container";
  networkEnabled: boolean;
};

Sandbox execution configuration (Issue #175)

sandbox.dockerImage?
optional dockerImage?: string;

Docker image to use in container mode (default: ‘node:22-alpine’)

sandbox.fallbackToPolicy
fallbackToPolicy: boolean;

Fall back to policy mode if container mode unavailable (default: true)

sandbox.mode
mode: "policy" | "none" | "container";

Sandbox execution mode (default: ‘policy’)

sandbox.networkEnabled
networkEnabled: boolean;

Enable network access in container mode (default: false)

secretsFile?
optional secretsFile?: string;
timeout?
optional timeout?: {
  defaultTimeoutMs: number;
  enableLogging: boolean;
  maxTimeoutMs: number;
  perToolTimeout?: Record<string, number>;
  uriValidation: boolean;
};

Timeout configuration (Issue #271, CVE-2026-0621)

timeout.defaultTimeoutMs
defaultTimeoutMs: number;

Default timeout in milliseconds (default: 30000)

timeout.enableLogging
enableLogging: boolean;

Whether to log timeout events (default: true)

timeout.maxTimeoutMs
maxTimeoutMs: number;

Maximum timeout in milliseconds (default: 300000)

timeout.perToolTimeout?
optional perToolTimeout?: Record<string, number>;

Per-tool timeout overrides in milliseconds (Issue #657)

timeout.uriValidation
uriValidation: boolean;

Enable URI validation to prevent ReDoS (default: true)

toolAllowlist?
optional toolAllowlist?: string[];

Tool allowlist — when set, only listed tools are registered (Issue #740)

Inherited from

BaseMcpToolDeps.security


PolicyFirewallConfig

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:105

Configuration for the policy firewall.

Properties

logger?
readonly optional logger?: ILogger;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:109

Logger instance

mode?
readonly optional mode?: PolicyMode;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:107

Enforcement mode (default: ‘enforce’)

rules?
readonly optional rules?: readonly FirewallPolicyRule[];

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:111

Initial rules to register


PromptDefinition

Defined in: packages/nexus-agents/src/mcp/prompts/prompt-definitions.ts:27

Declarative definition of an MCP prompt template.

  • argsSchema: Zod shape passed to server.registerPrompt
  • buildMessages: produces the message array from validated args

Properties

argsSchema
readonly argsSchema: Record<string, z.ZodType>;

Defined in: packages/nexus-agents/src/mcp/prompts/prompt-definitions.ts:30

buildMessages
readonly buildMessages: (args) => readonly PromptMessage[];

Defined in: packages/nexus-agents/src/mcp/prompts/prompt-definitions.ts:31

Parameters
args

Record<string, string | undefined>

Returns

readonly PromptMessage[]

description
readonly description: string;

Defined in: packages/nexus-agents/src/mcp/prompts/prompt-definitions.ts:29

name
readonly name: string;

Defined in: packages/nexus-agents/src/mcp/prompts/prompt-definitions.ts:28


PromptMessage

Defined in: packages/nexus-agents/src/mcp/prompts/prompt-definitions.ts:16

A single message in a prompt template.

Properties

content
readonly content: {
  text: string;
  type: "text";
};

Defined in: packages/nexus-agents/src/mcp/prompts/prompt-definitions.ts:18

text
readonly text: string;
type
readonly type: "text";
role
readonly role: "user" | "assistant";

Defined in: packages/nexus-agents/src/mcp/prompts/prompt-definitions.ts:17


PromptRegistrationResult

Defined in: packages/nexus-agents/src/mcp/prompts/index.ts:27

Result of prompt registration.

Properties

prompts
readonly prompts: readonly string[];

Defined in: packages/nexus-agents/src/mcp/prompts/index.ts:29

Names of registered prompts


PrReviewDeps

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:309

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports

Extends

Properties

gatewayAdapters?
optional gatewayAdapters?: readonly IModelAdapter[];

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:315

In-process gateway model adapters (#4040) — routes the review panel through the gateway (HTTP, in-process) instead of a CLI subprocess when configured. Omitted ⇒ CLI voter path.

logger?
optional logger?: ILogger;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:33

Optional logger

Inherited from

BaseMcpToolDeps.logger

rateLimiter
rateLimiter: McpRateLimiter;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:35

Rate limiter for throttling tool calls (required)

Inherited from

BaseMcpToolDeps.rateLimiter

security?
optional security?: {
  allowedPaths: string[];
  audit?: {
     enabled: boolean;
     enableHashChain: boolean;
     logDir?: string;
     maxFiles: number;
     maxFileSizeBytes: number;
     minSeverity: "critical" | "info" | "warning";
  };
  auth?: {
     enabled: boolean;
     method: "token" | "oauth2";
     tokenFile?: string;
     tokenHeader: string;
  };
  blockedPatterns: string[];
  policy?: {
     defaultMode: "read-only" | "read-write";
     policyMode: "warn" | "enforce";
  };
  rateLimit: {
     enabled: boolean;
     perTool?: Record<string, {
        capacity: number;
        refillIntervalMs: number;
        refillRate: number;
     }>;
     requestsPerMinute: number;
  };
  sandbox?: {
     dockerImage?: string;
     fallbackToPolicy: boolean;
     mode: "policy" | "none" | "container";
     networkEnabled: boolean;
  };
  secretsFile?: string;
  timeout?: {
     defaultTimeoutMs: number;
     enableLogging: boolean;
     maxTimeoutMs: number;
     perToolTimeout?: Record<string, number>;
     uriValidation: boolean;
  };
  toolAllowlist?: string[];
};

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:37

Security configuration (includes timeout settings)

allowedPaths
allowedPaths: string[];
audit?
optional audit?: {
  enabled: boolean;
  enableHashChain: boolean;
  logDir?: string;
  maxFiles: number;
  maxFileSizeBytes: number;
  minSeverity: "critical" | "info" | "warning";
};

Audit logging configuration (Issue #740 Phase 2).

The block is optional and the inner defaults only apply when it is present: a config with no audit: block is audit-OFF (initializeAuditLogger returns null and startup warns). config init writes the block explicitly so a generated config is on by default (#5632).

audit.enabled
enabled: boolean;

Enable audit logging (default when the block is present: true)

audit.enableHashChain
enableHashChain: boolean;

Enable tamper-evident hash chain (default: true)

audit.logDir?
optional logDir?: string;

Log directory (default: ~/.nexus-agents/audit)

audit.maxFiles
maxFiles: number;

Maximum number of log files to retain (default: 10)

audit.maxFileSizeBytes
maxFileSizeBytes: number;

Maximum log file size in bytes (default: 10MB)

audit.minSeverity
minSeverity: "critical" | "info" | "warning";

Minimum severity to log (default: ‘info’)

auth?
optional auth?: {
  enabled: boolean;
  method: "token" | "oauth2";
  tokenFile?: string;
  tokenHeader: string;
};

Authentication configuration (Issue #739)

auth.enabled
enabled: boolean;

Enable authentication for network-exposed transports (default: true)

auth.method
method: "token" | "oauth2";

Authentication method (default: ‘token’)

auth.tokenFile?
optional tokenFile?: string;

Token file path (default: ~/.nexus-agents/auth/server-token)

auth.tokenHeader
tokenHeader: string;

Header name for bearer token (default: ‘Authorization’)

blockedPatterns
blockedPatterns: string[];
policy?
optional policy?: {
  defaultMode: "read-only" | "read-write";
  policyMode: "warn" | "enforce";
};

Policy firewall configuration

policy.defaultMode
defaultMode: "read-only" | "read-write";

Execution mode for tool operations (default: ‘read-write’; ‘read-only’ is the opt-in lock, #6431)

policy.policyMode
policyMode: "warn" | "enforce";

Policy enforcement mode (default: ‘enforce’)

rateLimit
rateLimit: {
  enabled: boolean;
  perTool?: Record<string, {
     capacity: number;
     refillIntervalMs: number;
     refillRate: number;
  }>;
  requestsPerMinute: number;
};
rateLimit.enabled
enabled: boolean;
rateLimit.perTool?
optional perTool?: Record<string, {
  capacity: number;
  refillIntervalMs: number;
  refillRate: number;
}>;

Per-tool rate limits (Issue #274 Phase 2)

rateLimit.requestsPerMinute
requestsPerMinute: number;
sandbox?
optional sandbox?: {
  dockerImage?: string;
  fallbackToPolicy: boolean;
  mode: "policy" | "none" | "container";
  networkEnabled: boolean;
};

Sandbox execution configuration (Issue #175)

sandbox.dockerImage?
optional dockerImage?: string;

Docker image to use in container mode (default: ‘node:22-alpine’)

sandbox.fallbackToPolicy
fallbackToPolicy: boolean;

Fall back to policy mode if container mode unavailable (default: true)

sandbox.mode
mode: "policy" | "none" | "container";

Sandbox execution mode (default: ‘policy’)

sandbox.networkEnabled
networkEnabled: boolean;

Enable network access in container mode (default: false)

secretsFile?
optional secretsFile?: string;
timeout?
optional timeout?: {
  defaultTimeoutMs: number;
  enableLogging: boolean;
  maxTimeoutMs: number;
  perToolTimeout?: Record<string, number>;
  uriValidation: boolean;
};

Timeout configuration (Issue #271, CVE-2026-0621)

timeout.defaultTimeoutMs
defaultTimeoutMs: number;

Default timeout in milliseconds (default: 30000)

timeout.enableLogging
enableLogging: boolean;

Whether to log timeout events (default: true)

timeout.maxTimeoutMs
maxTimeoutMs: number;

Maximum timeout in milliseconds (default: 300000)

timeout.perToolTimeout?
optional perToolTimeout?: Record<string, number>;

Per-tool timeout overrides in milliseconds (Issue #657)

timeout.uriValidation
uriValidation: boolean;

Enable URI validation to prevent ReDoS (default: true)

toolAllowlist?
optional toolAllowlist?: string[];

Tool allowlist — when set, only listed tools are registered (Issue #740)

Inherited from

BaseMcpToolDeps.security


PrReviewResponse

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:267

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports

Properties

abstainCount
readonly abstainCount: number;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:275

approveCount
readonly approveCount: number;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:273

costSummary?
readonly optional costSummary?: DecisionCostSummary;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:293

Per-decision cost rollup (#3855): per-voter / per-model token + USD totals for this governed review. Rides the existing response — no new MCP tool. Totals are a floor when costSummary.unmeasuredVoters > 0 (voters whose adapter reported no usage are counted as unmeasured, not a measured $0).

coverage?
readonly optional coverage?: PrReviewBindingCoverage;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:306

Large-diff review coverage (#4140, #6003). Present when the panel read a packed subset (panelRead: 'partial') OR the audit hash binds only a prefix of the diff (binding: 'prefix'); absent when both are full. Byte fields are UTF-8.

errorCount
readonly errorCount: number;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:276

project
readonly project: ResolvedVoterProject;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:286

The project the panel judged and how the name was decided (#6123): the caller’s project input, else derived from the server’s working directory, else nexus-agents. Always present.

recordOutcome?
readonly optional recordOutcome?: PrReviewRecordOutcome;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:299

Option-C audit-record persistence outcome (#4031). Present on every response: persisted: true with the record’s binding + sequence when an authentic record was written, otherwise persisted: false with the reason.

requestChangesCount
readonly requestChangesCount: number;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:274

reviews
readonly reviews: readonly PrReviewVote[];

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:279

summary
readonly summary: PrReviewDecision;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:268

totalDurationMs
readonly totalDurationMs: number;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:280

unverifiableCount
readonly unverifiableCount: number;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:278

Seats that could not read the diff (#6094). Always present; not inside abstainCount.

verified
readonly verified: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:272

True when the request_changes / approve outcome was driven by verified findings or unanimous approval; false when the outcome is a soft signal (majority dissent without verified findings).


PrReviewVote

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:229

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports

Properties

cli?
readonly optional cli?: string;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:243

confidence
readonly confidence: number;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:232

decision
readonly decision: PrReviewDecision;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:231

errorMessage?
readonly optional errorMessage?: string;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:245

findings
readonly findings: readonly Finding[];

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:240

Structured findings parsed from the voter’s reasoning per #2225 + #2233 Child 3. Each Finding has a verification gate output and a derived verified boolean. Only verified findings can trigger request_changes — see aggregatePrDecisions.

processingTimeMs
readonly processingTimeMs: number;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:244

reasoning
readonly reasoning: string;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:235

Free-form reasoning from the voter — full text including the findings YAML block (which is also parsed into findings below).

role
readonly role: VoterRole;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:230

source
readonly source: "error" | "llm" | "unverifiable" | "simulation";

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:242

Derived from the canonical union so a new seat kind (#6094) cannot be dropped here.


RateLimiterState

Defined in: packages/nexus-agents/src/mcp/middleware/rate-limiter.ts:31

Current state of the rate limiter.

Properties

capacity
readonly capacity: number;

Defined in: packages/nexus-agents/src/mcp/middleware/rate-limiter.ts:35

Capacity of the bucket

nextTokenMs
readonly nextTokenMs: number;

Defined in: packages/nexus-agents/src/mcp/middleware/rate-limiter.ts:37

Time until next token is available (0 if tokens available)

tokens
readonly tokens: number;

Defined in: packages/nexus-agents/src/mcp/middleware/rate-limiter.ts:33

Current number of available tokens


RegistryRelationship

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:30

A relationship edge between scanners.

Properties

target
readonly target: string;

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:31

type
readonly type: "supersedes" | "uses" | "bundles" | "competes-with";

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:32


RegistryScanner

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:20

A scanner entry from the registry manifest.

Properties

categories
readonly categories: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:23

displayName
readonly displayName: string;

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:22

license
readonly license: string;

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:24

name
readonly name: string;

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:21

pricingModel
readonly pricingModel: string;

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:25

relationships?
readonly optional relationships?: readonly RegistryRelationship[];

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:26


RepoAnalysis

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze-types.ts:47

Structured analysis of a GitHub repository.

Properties

ciProvider
readonly ciProvider: string | null;

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze-types.ts:57

CI provider (e.g., “github-actions”, “concourse”, “jenkins”).

defaultBranch
readonly defaultBranch: string;

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze-types.ts:98

Default branch name.

description
readonly description: string | null;

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze-types.ts:96

Repository description.

framework
readonly framework: string | null;

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze-types.ts:53

Detected framework (e.g., “express”, “react”, “spring-boot”).

gaps
readonly gaps: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze-types.ts:104

Identified gaps or missing best practices.

hasDockerfile
readonly hasDockerfile: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze-types.ts:61

Whether the repo has a Dockerfile.

hasHelmCharts
readonly hasHelmCharts: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze-types.ts:63

Whether the repo has Helm charts.

hasMakefile
readonly hasMakefile: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze-types.ts:65

Whether the repo has a Makefile.

hasTests
readonly hasTests: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze-types.ts:71

Whether the repo has tests. Only meaningful when testsMeasured is true — false alone cannot distinguish “no tests” from “no probe for this language” (#6018).

language
readonly language: string | null;

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze-types.ts:51

Primary programming language.

license
readonly license: string | null;

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze-types.ts:94

License type (e.g., “MIT”, “Apache-2.0”).

name
readonly name: string;

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze-types.ts:49

Repository name with owner (e.g., “owner/repo”).

packageManager
readonly packageManager: string | null;

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze-types.ts:55

Package manager (e.g., “npm”, “pip”, “maven”, “cargo”).

securityTooling
readonly securityTooling: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze-types.ts:59

Security tooling detected in the repo.

stars
readonly stars: number;

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze-types.ts:100

Star count.

testsMeasured
readonly testsMeasured: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze-types.ts:82

Whether test detection had a rule for this repo’s language (#6018).

REQUIRED, not optional, so the compiler names every producer. Before this, hasTests: false was emitted for any language the JS-shaped probes did not cover, and a Rust workspace with 1385 #[test] functions reported “No test directory detected” — a default wearing the costume of a measurement. When this is false the gap list stays silent rather than asserting an absence nobody checked.

topLevelEntries
readonly topLevelEntries: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze-types.ts:102

Top-level directory listing.

workflowsMeasured
readonly workflowsMeasured: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze-types.ts:92

Whether .github/workflows/ was actually listed (#6035).

REQUIRED, not optional: an optional flag lets a construction site omit it and inherit the confident default, which is the shape that produced the bug. False ⇒ CI-level security tooling is unmeasured, and the SAST gap is reported as unverified rather than asserted.


RepoSecurityPlan

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:67

Complete security scanning plan for a repository.

Properties

ciProvider
readonly ciProvider: string | null;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:71

conflicts
readonly conflicts: readonly ConflictWarning[];

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:74

coverage
readonly coverage: readonly CoverageAnalysis[];

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:75

existingTooling
readonly existingTooling: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:72

framework
readonly framework: string | null;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:70

gapsSummary
readonly gapsSummary: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:76

language
readonly language: string | null;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:69

recommendations
readonly recommendations: readonly ScannerRecommendation[];

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:73

repo
readonly repo: string;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:68

scannerDataAgeMs?
readonly optional scannerDataAgeMs?: number;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:91

Age of the cached scanner data when scannerDataSource is ‘cache’.

scannerDataSource
readonly scannerDataSource: "cache" | "registry" | "fallback";

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:89

Where the scanner data behind this plan came from (#6037).

REQUIRED, because the whole defect was that it could be absent: the value was computed in resolveScannerData and discarded at this boundary, so a plan built from FALLBACK_SCANNER_DATA — or from a cache with no age bound — read exactly like one built against the live registry, under a tool description promising “provenance-tracked metrics”.

cache is deliberately distinct from registry: CACHE_TTL_MS gates only whether to REFETCH, so the stale-cache path returns an entry of any age.


ResearchAddResponse

Defined in: packages/nexus-agents/src/mcp/tools/research-add.ts:72

Response from research_add tool.

Properties

dryRun
dryRun: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/research-add.ts:82

Whether this was a dry run

errorCategory?
optional errorCategory?: "validation" | "internal" | "transient" | "permission" | "business";

Defined in: packages/nexus-agents/src/mcp/tools/research-add.ts:88

Error category when success is false (#2649). business for a dedup hit (paper already in registry); absent otherwise — the MCP handler treats absent as internal.

message
message: string;

Defined in: packages/nexus-agents/src/mcp/tools/research-add.ts:80

Human-readable message

paperId
paperId: string;

Defined in: packages/nexus-agents/src/mcp/tools/research-add.ts:76

Paper ID

success
success: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/research-add.ts:74

Whether the operation succeeded

title
title: string;

Defined in: packages/nexus-agents/src/mcp/tools/research-add.ts:78

Paper title (empty on failure)


ResearchAddSourceResponse

Defined in: packages/nexus-agents/src/mcp/tools/research-add-source.ts:86

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports

Properties

dryRun
dryRun: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/research-add-source.ts:93

errorCategory?
optional errorCategory?: "validation" | "internal" | "transient" | "permission" | "business";

Defined in: packages/nexus-agents/src/mcp/tools/research-add-source.ts:99

Error category when success is false (#2649). business for a dedup hit (source already in registry), internal for a write failure; absent otherwise.

evidence_tier
evidence_tier: string;

Defined in: packages/nexus-agents/src/mcp/tools/research-add-source.ts:91

message
message: string;

Defined in: packages/nexus-agents/src/mcp/tools/research-add-source.ts:92

name
name: string;

Defined in: packages/nexus-agents/src/mcp/tools/research-add-source.ts:89

quality_score
quality_score: number;

Defined in: packages/nexus-agents/src/mcp/tools/research-add-source.ts:90

sourceId
sourceId: string;

Defined in: packages/nexus-agents/src/mcp/tools/research-add-source.ts:88

success
success: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/research-add-source.ts:87


ResearchAnalyzeResponse

Defined in: packages/nexus-agents/src/mcp/tools/research-analyze.ts:67

Response from research_analyze tool.

Properties

analysis
analysis: unknown;

Defined in: packages/nexus-agents/src/mcp/tools/research-analyze.ts:73

Analysis results

focus
focus: string;

Defined in: packages/nexus-agents/src/mcp/tools/research-analyze.ts:69

Analysis focus that was performed

recommendations
recommendations: string[];

Defined in: packages/nexus-agents/src/mcp/tools/research-analyze.ts:75

Recommendations based on analysis

success
success: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/research-analyze.ts:71

Whether the analysis succeeded


ResearchDiscoverResponse

Defined in: packages/nexus-agents/src/mcp/tools/research-discover.ts:177

Response from research_discover tool.

Properties

alreadyInRegistry
alreadyInRegistry: number;

Defined in: packages/nexus-agents/src/mcp/tools/research-discover.ts:195

Items already in registry (filtered out).

Meaningful ONLY when registryConsulted is true. When the registry could not be read this is 0 because nothing could be matched, not because nothing matched.

failedSources
failedSources: string[];

Defined in: packages/nexus-agents/src/mcp/tools/research-discover.ts:183

Sources that failed during discovery

filteredByRelevance
filteredByRelevance: number;

Defined in: packages/nexus-agents/src/mcp/tools/research-discover.ts:208

Items filtered out by relevance threshold

items
items: DiscoveredItem[];

Defined in: packages/nexus-agents/src/mcp/tools/research-discover.ts:185

Discovered items

newItems
newItems: number;

Defined in: packages/nexus-agents/src/mcp/tools/research-discover.ts:206

New items not yet in registry

registryConsulted
registryConsulted: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/research-discover.ts:204

Whether the papers registry was actually read (#5925).

false means the dedup pass did not run: every item is reported as new regardless of what the registry holds. Required rather than optional so every construction site has to answer, and so a caller cannot silently inherit a default.

sourcesQueried
sourcesQueried: string[];

Defined in: packages/nexus-agents/src/mcp/tools/research-discover.ts:181

Sources queried

topic
topic: string;

Defined in: packages/nexus-agents/src/mcp/tools/research-discover.ts:179

Topic that was searched

totalFound
totalFound: number;

Defined in: packages/nexus-agents/src/mcp/tools/research-discover.ts:187

Total items found (before filtering)


ResearchQueryResponse

Defined in: packages/nexus-agents/src/mcp/tools/research-query.ts:97

Response from research_query tool.

Properties

action
action: string;

Defined in: packages/nexus-agents/src/mcp/tools/research-query.ts:99

Action that was performed

data
data: unknown;

Defined in: packages/nexus-agents/src/mcp/tools/research-query.ts:103

Query results

negativeResults?
optional negativeResults?: {
  reason: string;
  status: "unavailable";
};

Defined in: packages/nexus-agents/src/mcp/tools/research-query.ts:113

Present when the negative-results registry could not be measured.

reason
reason: string;
status
status: "unavailable";
rejectionNotice?
optional rejectionNotice?: string;

Defined in: packages/nexus-agents/src/mcp/tools/research-query.ts:111

A recorded rejection for the queried technique, when one exists (#4555).

Advisory. The registry says a prior attempt failed and why; it does not suppress the result, because a prior rejection is evidence to weigh, not a veto.

success
success: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/research-query.ts:101

Whether the query succeeded


RunGraphWorkflowDeps

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow.ts:84

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports

Extends

Properties

auditLogger?
readonly optional auditLogger?: IAuditLogger;

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow.ts:95

Durable audit logger (#5219). Without it, enableAuditTrail produced a trail that was never persisted: graph_execution records sat in an in-memory array capped at 10,000, evicted oldest-first, and gone on exit — never reaching the hash chain verify_audit_chain reads.

Threaded the same way execute_expert and orchestrate receive theirs.

logger?
optional logger?: ILogger;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:33

Optional logger

Inherited from

BaseMcpToolDeps.logger

notifier?
readonly optional notifier?: IMcpNotifier;

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow.ts:86

MCP notifier for client-visible logging (Issue #974)

rateLimiter
rateLimiter: McpRateLimiter;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:35

Rate limiter for throttling tool calls (required)

Inherited from

BaseMcpToolDeps.rateLimiter

security?
optional security?: {
  allowedPaths: string[];
  audit?: {
     enabled: boolean;
     enableHashChain: boolean;
     logDir?: string;
     maxFiles: number;
     maxFileSizeBytes: number;
     minSeverity: "critical" | "info" | "warning";
  };
  auth?: {
     enabled: boolean;
     method: "token" | "oauth2";
     tokenFile?: string;
     tokenHeader: string;
  };
  blockedPatterns: string[];
  policy?: {
     defaultMode: "read-only" | "read-write";
     policyMode: "warn" | "enforce";
  };
  rateLimit: {
     enabled: boolean;
     perTool?: Record<string, {
        capacity: number;
        refillIntervalMs: number;
        refillRate: number;
     }>;
     requestsPerMinute: number;
  };
  sandbox?: {
     dockerImage?: string;
     fallbackToPolicy: boolean;
     mode: "policy" | "none" | "container";
     networkEnabled: boolean;
  };
  secretsFile?: string;
  timeout?: {
     defaultTimeoutMs: number;
     enableLogging: boolean;
     maxTimeoutMs: number;
     perToolTimeout?: Record<string, number>;
     uriValidation: boolean;
  };
  toolAllowlist?: string[];
};

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:37

Security configuration (includes timeout settings)

allowedPaths
allowedPaths: string[];
audit?
optional audit?: {
  enabled: boolean;
  enableHashChain: boolean;
  logDir?: string;
  maxFiles: number;
  maxFileSizeBytes: number;
  minSeverity: "critical" | "info" | "warning";
};

Audit logging configuration (Issue #740 Phase 2).

The block is optional and the inner defaults only apply when it is present: a config with no audit: block is audit-OFF (initializeAuditLogger returns null and startup warns). config init writes the block explicitly so a generated config is on by default (#5632).

audit.enabled
enabled: boolean;

Enable audit logging (default when the block is present: true)

audit.enableHashChain
enableHashChain: boolean;

Enable tamper-evident hash chain (default: true)

audit.logDir?
optional logDir?: string;

Log directory (default: ~/.nexus-agents/audit)

audit.maxFiles
maxFiles: number;

Maximum number of log files to retain (default: 10)

audit.maxFileSizeBytes
maxFileSizeBytes: number;

Maximum log file size in bytes (default: 10MB)

audit.minSeverity
minSeverity: "critical" | "info" | "warning";

Minimum severity to log (default: ‘info’)

auth?
optional auth?: {
  enabled: boolean;
  method: "token" | "oauth2";
  tokenFile?: string;
  tokenHeader: string;
};

Authentication configuration (Issue #739)

auth.enabled
enabled: boolean;

Enable authentication for network-exposed transports (default: true)

auth.method
method: "token" | "oauth2";

Authentication method (default: ‘token’)

auth.tokenFile?
optional tokenFile?: string;

Token file path (default: ~/.nexus-agents/auth/server-token)

auth.tokenHeader
tokenHeader: string;

Header name for bearer token (default: ‘Authorization’)

blockedPatterns
blockedPatterns: string[];
policy?
optional policy?: {
  defaultMode: "read-only" | "read-write";
  policyMode: "warn" | "enforce";
};

Policy firewall configuration

policy.defaultMode
defaultMode: "read-only" | "read-write";

Execution mode for tool operations (default: ‘read-write’; ‘read-only’ is the opt-in lock, #6431)

policy.policyMode
policyMode: "warn" | "enforce";

Policy enforcement mode (default: ‘enforce’)

rateLimit
rateLimit: {
  enabled: boolean;
  perTool?: Record<string, {
     capacity: number;
     refillIntervalMs: number;
     refillRate: number;
  }>;
  requestsPerMinute: number;
};
rateLimit.enabled
enabled: boolean;
rateLimit.perTool?
optional perTool?: Record<string, {
  capacity: number;
  refillIntervalMs: number;
  refillRate: number;
}>;

Per-tool rate limits (Issue #274 Phase 2)

rateLimit.requestsPerMinute
requestsPerMinute: number;
sandbox?
optional sandbox?: {
  dockerImage?: string;
  fallbackToPolicy: boolean;
  mode: "policy" | "none" | "container";
  networkEnabled: boolean;
};

Sandbox execution configuration (Issue #175)

sandbox.dockerImage?
optional dockerImage?: string;

Docker image to use in container mode (default: ‘node:22-alpine’)

sandbox.fallbackToPolicy
fallbackToPolicy: boolean;

Fall back to policy mode if container mode unavailable (default: true)

sandbox.mode
mode: "policy" | "none" | "container";

Sandbox execution mode (default: ‘policy’)

sandbox.networkEnabled
networkEnabled: boolean;

Enable network access in container mode (default: false)

secretsFile?
optional secretsFile?: string;
timeout?
optional timeout?: {
  defaultTimeoutMs: number;
  enableLogging: boolean;
  maxTimeoutMs: number;
  perToolTimeout?: Record<string, number>;
  uriValidation: boolean;
};

Timeout configuration (Issue #271, CVE-2026-0621)

timeout.defaultTimeoutMs
defaultTimeoutMs: number;

Default timeout in milliseconds (default: 30000)

timeout.enableLogging
enableLogging: boolean;

Whether to log timeout events (default: true)

timeout.maxTimeoutMs
maxTimeoutMs: number;

Maximum timeout in milliseconds (default: 300000)

timeout.perToolTimeout?
optional perToolTimeout?: Record<string, number>;

Per-tool timeout overrides in milliseconds (Issue #657)

timeout.uriValidation
uriValidation: boolean;

Enable URI validation to prevent ReDoS (default: true)

toolAllowlist?
optional toolAllowlist?: string[];

Tool allowlist — when set, only listed tools are registered (Issue #740)

Inherited from

BaseMcpToolDeps.security


RunGraphWorkflowResponse

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow.ts:98

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports

Properties

checkpointCount
readonly checkpointCount: number;

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow.ts:106

durationMs
readonly durationMs: number;

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow.ts:104

error?
readonly optional error?: string;

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow.ts:107

events
readonly events: readonly GraphEventSummary[];

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow.ts:105

finalState
readonly finalState: Readonly<GraphState>;

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow.ts:101

nodesExecuted
readonly nodesExecuted: number;

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow.ts:103

status
readonly status: "failed" | "completed";

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow.ts:100

stepsExecuted
readonly stepsExecuted: number;

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow.ts:102

workflow
readonly workflow: string;

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow.ts:99


RunWorkflowDeps

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:161

Dependencies required by the run_workflow tool.

Extends

Properties

logger?
optional logger?: ILogger;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:33

Optional logger

Inherited from

BaseMcpToolDeps.logger

notifier?
optional notifier?: IMcpNotifier;

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:195

MCP notifier for client-visible logging (Issue #974)

rateLimiter
rateLimiter: McpRateLimiter;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:35

Rate limiter for throttling tool calls (required)

Inherited from

BaseMcpToolDeps.rateLimiter

resolveExecutionEngine?
optional resolveExecutionEngine?: () => IWorkflowEngine;

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:193

Resolves the engine that actually EXECUTES, at call time (#5116).

A THUNK rather than a value because constructing an executing engine throws WorkflowExecutionUnavailableError under the #507 fail-safe when nothing can execute for real — doing that eagerly at tool registration killed the whole server, all 47 tools, over one unconfigured adapter.

OPTIONAL rather than required, by unanimous panel decision. It was briefly required, which is how all eight internal call sites were enumerated by the compiler — that value is already banked. Keeping it required would make this a breaking change to a publicly exported type (exports/mcp.ts) and gate a p1 correctness fix behind a major version.

Defaulting to workflowEngine is semantically correct for an external caller, not merely compile-compatible: their single engine genuinely serves both listing and execution, so the fallback preserves exactly what they had. The residual hazard — a future INTERNAL call site omitting this and executing against a listing engine — is covered two ways: a test asserting the production registration supplies it, and the listing engine failing closed rather than returning a fabricated success.

Returns

IWorkflowEngine

security?
optional security?: {
  allowedPaths: string[];
  audit?: {
     enabled: boolean;
     enableHashChain: boolean;
     logDir?: string;
     maxFiles: number;
     maxFileSizeBytes: number;
     minSeverity: "critical" | "info" | "warning";
  };
  auth?: {
     enabled: boolean;
     method: "token" | "oauth2";
     tokenFile?: string;
     tokenHeader: string;
  };
  blockedPatterns: string[];
  policy?: {
     defaultMode: "read-only" | "read-write";
     policyMode: "warn" | "enforce";
  };
  rateLimit: {
     enabled: boolean;
     perTool?: Record<string, {
        capacity: number;
        refillIntervalMs: number;
        refillRate: number;
     }>;
     requestsPerMinute: number;
  };
  sandbox?: {
     dockerImage?: string;
     fallbackToPolicy: boolean;
     mode: "policy" | "none" | "container";
     networkEnabled: boolean;
  };
  secretsFile?: string;
  timeout?: {
     defaultTimeoutMs: number;
     enableLogging: boolean;
     maxTimeoutMs: number;
     perToolTimeout?: Record<string, number>;
     uriValidation: boolean;
  };
  toolAllowlist?: string[];
};

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:37

Security configuration (includes timeout settings)

allowedPaths
allowedPaths: string[];
audit?
optional audit?: {
  enabled: boolean;
  enableHashChain: boolean;
  logDir?: string;
  maxFiles: number;
  maxFileSizeBytes: number;
  minSeverity: "critical" | "info" | "warning";
};

Audit logging configuration (Issue #740 Phase 2).

The block is optional and the inner defaults only apply when it is present: a config with no audit: block is audit-OFF (initializeAuditLogger returns null and startup warns). config init writes the block explicitly so a generated config is on by default (#5632).

audit.enabled
enabled: boolean;

Enable audit logging (default when the block is present: true)

audit.enableHashChain
enableHashChain: boolean;

Enable tamper-evident hash chain (default: true)

audit.logDir?
optional logDir?: string;

Log directory (default: ~/.nexus-agents/audit)

audit.maxFiles
maxFiles: number;

Maximum number of log files to retain (default: 10)

audit.maxFileSizeBytes
maxFileSizeBytes: number;

Maximum log file size in bytes (default: 10MB)

audit.minSeverity
minSeverity: "critical" | "info" | "warning";

Minimum severity to log (default: ‘info’)

auth?
optional auth?: {
  enabled: boolean;
  method: "token" | "oauth2";
  tokenFile?: string;
  tokenHeader: string;
};

Authentication configuration (Issue #739)

auth.enabled
enabled: boolean;

Enable authentication for network-exposed transports (default: true)

auth.method
method: "token" | "oauth2";

Authentication method (default: ‘token’)

auth.tokenFile?
optional tokenFile?: string;

Token file path (default: ~/.nexus-agents/auth/server-token)

auth.tokenHeader
tokenHeader: string;

Header name for bearer token (default: ‘Authorization’)

blockedPatterns
blockedPatterns: string[];
policy?
optional policy?: {
  defaultMode: "read-only" | "read-write";
  policyMode: "warn" | "enforce";
};

Policy firewall configuration

policy.defaultMode
defaultMode: "read-only" | "read-write";

Execution mode for tool operations (default: ‘read-write’; ‘read-only’ is the opt-in lock, #6431)

policy.policyMode
policyMode: "warn" | "enforce";

Policy enforcement mode (default: ‘enforce’)

rateLimit
rateLimit: {
  enabled: boolean;
  perTool?: Record<string, {
     capacity: number;
     refillIntervalMs: number;
     refillRate: number;
  }>;
  requestsPerMinute: number;
};
rateLimit.enabled
enabled: boolean;
rateLimit.perTool?
optional perTool?: Record<string, {
  capacity: number;
  refillIntervalMs: number;
  refillRate: number;
}>;

Per-tool rate limits (Issue #274 Phase 2)

rateLimit.requestsPerMinute
requestsPerMinute: number;
sandbox?
optional sandbox?: {
  dockerImage?: string;
  fallbackToPolicy: boolean;
  mode: "policy" | "none" | "container";
  networkEnabled: boolean;
};

Sandbox execution configuration (Issue #175)

sandbox.dockerImage?
optional dockerImage?: string;

Docker image to use in container mode (default: ‘node:22-alpine’)

sandbox.fallbackToPolicy
fallbackToPolicy: boolean;

Fall back to policy mode if container mode unavailable (default: true)

sandbox.mode
mode: "policy" | "none" | "container";

Sandbox execution mode (default: ‘policy’)

sandbox.networkEnabled
networkEnabled: boolean;

Enable network access in container mode (default: false)

secretsFile?
optional secretsFile?: string;
timeout?
optional timeout?: {
  defaultTimeoutMs: number;
  enableLogging: boolean;
  maxTimeoutMs: number;
  perToolTimeout?: Record<string, number>;
  uriValidation: boolean;
};

Timeout configuration (Issue #271, CVE-2026-0621)

timeout.defaultTimeoutMs
defaultTimeoutMs: number;

Default timeout in milliseconds (default: 30000)

timeout.enableLogging
enableLogging: boolean;

Whether to log timeout events (default: true)

timeout.maxTimeoutMs
maxTimeoutMs: number;

Maximum timeout in milliseconds (default: 300000)

timeout.perToolTimeout?
optional perToolTimeout?: Record<string, number>;

Per-tool timeout overrides in milliseconds (Issue #657)

timeout.uriValidation
uriValidation: boolean;

Enable URI validation to prevent ReDoS (default: true)

toolAllowlist?
optional toolAllowlist?: string[];

Tool allowlist — when set, only listed tools are registered (Issue #740)

Inherited from

BaseMcpToolDeps.security

workflowEngine
workflowEngine: IWorkflowEngine;

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:170

Engine used to ENUMERATE and load templates — listTemplates, getTemplateByName, loadTemplate. Never used to execute.

Listing needs no model adapter, so this engine is constructible on a fresh install with no credentials. That is the capability split #5116 turns on: enumerating workflows and running them have different prerequisites.


ScannerData

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan.ts:51

Resolved scanner data for plan building.

Properties

ageMs?
readonly optional ageMs?: number;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan.ts:61

Age of the cached data when source is ‘cache’.

languageMap
readonly languageMap: Readonly<Record<string, LanguageMapping>>;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan.ts:53

scanners
readonly scanners: readonly ScannerEntry[];

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan.ts:52

source
readonly source: "cache" | "registry" | "fallback";

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan.ts:59

Where the scanner data came from (#6037). THREE states, not two: a stale cache is not a live registry read, and it used to be stamped ‘registry’ because the only test was manifest !== null.


ScannerEntry

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan.ts:34

Internal scanner entry used by plan builder.

Properties

categories
readonly categories: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan.ts:37

displayName
readonly displayName: string;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan.ts:36

license
readonly license: string;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan.ts:38

name
readonly name: string;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan.ts:35

pricingModel
readonly pricingModel: string;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan.ts:39

supersedes?
readonly optional supersedes?: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan.ts:40


ScannerRecommendation

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:41

A single scanner recommendation with rationale.

Properties

category
readonly category: string;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:44

ciSnippet
readonly ciSnippet: string | null;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:49

displayName
readonly displayName: string;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:43

license
readonly license: string;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:45

name
readonly name: string;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:42

pricingModel
readonly pricingModel: string;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:46

priority
readonly priority: "optional" | "critical" | "recommended";

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:48

rationale
readonly rationale: string;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:47


ScannerRegistryManifest

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:46

The full registry manifest shape.

Properties

generatedAt
readonly generatedAt: string;

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:48

languageMatrix
readonly languageMatrix: Readonly<Record<string, LanguageMatrixEntry>>;

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:50

scanners
readonly scanners: readonly RegistryScanner[];

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:49

version
readonly version: string;

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:47


ServerConfig

Defined in: packages/nexus-agents/src/mcp/server.ts:33

Server configuration options.

Properties

logger?
readonly optional logger?: ILogger;

Defined in: packages/nexus-agents/src/mcp/server.ts:39

Logger instance

name?
readonly optional name?: string;

Defined in: packages/nexus-agents/src/mcp/server.ts:35

Server name (default: “nexus-agents”)

version?
readonly optional version?: string;

Defined in: packages/nexus-agents/src/mcp/server.ts:37

Server version (default: package version)


ServerError

Defined in: packages/nexus-agents/src/mcp/server.ts:55

Error type for server operations.

Properties

cause?
optional cause?: Error;

Defined in: packages/nexus-agents/src/mcp/server.ts:58

code
code: 
  | "SERVER_CREATION_FAILED"
  | "SERVER_START_FAILED"
  | "SERVER_STOP_FAILED";

Defined in: packages/nexus-agents/src/mcp/server.ts:56

message
message: string;

Defined in: packages/nexus-agents/src/mcp/server.ts:57


ServerInstance

Defined in: packages/nexus-agents/src/mcp/server.ts:45

Server creation result containing the server and logger.

Properties

logger
readonly logger: ILogger;

Defined in: packages/nexus-agents/src/mcp/server.ts:49

The logger instance for this server

server
readonly server: McpServer;

Defined in: packages/nexus-agents/src/mcp/server.ts:47

The MCP server instance


StepResultSummary

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:134

Simplified step result for tool output.

Properties

durationMs
durationMs: number;

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:137

error?
optional error?: string;

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:138

status
status: "success" | "failed" | "skipped";

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:136

stepId
stepId: string;

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:135


TaskRequirements

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:135

Analyzes task to determine requirements.

Properties

estimatedTokens
estimatedTokens: number;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:136

isCostSensitive
isCostSensitive: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:141

needsAudioOutput
needsAudioOutput: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:145

Whether the task requires audio output (Issue #685)

needsCodeGen
needsCodeGen: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:140

needsExploration
needsExploration: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:149

Whether the task is exploration/research (benefits from large context) (Issue #807)

needsImageGen
needsImageGen: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:143

Whether the task requires image generation output (Issue #685)

needsLargeContext
needsLargeContext: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:138

needsMcp
needsMcp: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:147

Whether the task requires MCP tool support (Issue #685)

needsReasoning
needsReasoning: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:137

needsSpeed
needsSpeed: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:139


TextContent

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:47

MCP tool content types.

Properties

text
text: string;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:49

type
type: "text";

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:48


ToolRegistrationOptions

Defined in: packages/nexus-agents/src/mcp/tools/index.ts:556

Options for tool registration.

Properties

logger?
readonly optional logger?: ILogger;

Defined in: packages/nexus-agents/src/mcp/tools/index.ts:558

Logger instance for tool operations

rateLimiter?
readonly optional rateLimiter?: McpRateLimiter;

Defined in: packages/nexus-agents/src/mcp/tools/index.ts:560

Rate limiter for tool calls


ToolRegistrationResult

Defined in: packages/nexus-agents/src/mcp/tools/index.ts:566

Result of tool registration.

Properties

logger
readonly logger: ILogger;

Defined in: packages/nexus-agents/src/mcp/tools/index.ts:570

Logger used for tool operations

rateLimiter
readonly rateLimiter: McpRateLimiter;

Defined in: packages/nexus-agents/src/mcp/tools/index.ts:572

Rate limiter used for tool calls

tools
readonly tools: readonly string[];

Defined in: packages/nexus-agents/src/mcp/tools/index.ts:568

Names of registered tools


ToolResult

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:58

MCP tool result.

Uses mutable properties for compatibility with secure-handler sanitization (which rewrites text in-place).

Properties

_meta?
optional _meta?: Record<string, unknown>;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:68

Out-of-band metadata, never validated against outputSchema. The structured error envelope (#2649) is carried here under ERROR_ENVELOPE_META_KEY.

content
content: TextContent[];

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:59

isError?
optional isError?: boolean;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:60

structuredContent?
optional structuredContent?: Record<string, unknown>;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:62

Structured output for SDK outputSchema validation (Issue #1117)


WorkflowInfo

Defined in: packages/nexus-agents/src/mcp/tools/list-workflows.ts:56

Workflow information returned by list_workflows tool.

Properties

category
category: string | undefined;

Defined in: packages/nexus-agents/src/mcp/tools/list-workflows.ts:64

Workflow category

description
description: string | undefined;

Defined in: packages/nexus-agents/src/mcp/tools/list-workflows.ts:62

Workflow description

name
name: string;

Defined in: packages/nexus-agents/src/mcp/tools/list-workflows.ts:58

Template name for run_workflow

version
version: string;

Defined in: packages/nexus-agents/src/mcp/tools/list-workflows.ts:60

Version string


WorkflowToolResult

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:111

Workflow execution result returned by the tool.

Properties

budget?
optional budget?: WorkflowBudgetReport;

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:119

Token-budget report (#4754). Absent when no ceiling was requested or resolved.

durationMs
durationMs: number;

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:117

executionId
executionId: string;

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:112

output
output: unknown;

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:116

status
status: "failed" | "completed";

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:114

stepResults
stepResults: StepResultSummary[];

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:115

workflowName
workflowName: string;

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:113


CancelJobDeps

type CancelJobDeps = BaseMcpToolDeps;

Defined in: packages/nexus-agents/src/mcp/tools/cancel-job-tool.ts:79

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


CancelJobInput

type CancelJobInput = z.infer<typeof CancelJobInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/cancel-job-tool.ts:66

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


ConsensusVoteInput

type ConsensusVoteInput = z.infer<typeof ConsensusVoteInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:342

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


CreateExpertInput

type CreateExpertInput = z.infer<typeof CreateExpertInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/create-expert.ts:87

Type for validated create expert input.


DelegateInput

type DelegateInput = z.infer<typeof DelegateInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:79

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


DelegateOutput

type DelegateOutput = z.infer<typeof DelegateOutputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:118

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


ExecuteExpertInput

type ExecuteExpertInput = z.infer<typeof ExecuteExpertInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/execute-expert.ts:100

Type for validated execute expert input.


ExecuteSpecDeps

type ExecuteSpecDeps = BaseMcpToolDeps;

Defined in: packages/nexus-agents/src/mcp/tools/execute-spec-tool.ts:64

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


ExecuteSpecInput

type ExecuteSpecInput = z.infer<typeof ExecuteSpecInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/execute-spec-tool.ts:62

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


ExecutionMode

type ExecutionMode = "read-only" | "read-write";

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:35

Execution mode for tool operations.

  • ‘read-only’: Only read operations allowed — the operator’s opt-in lock
  • ‘read-write’: Both read and write operations allowed (default since #6431; DEFAULT_EXECUTION_MODE in config/schemas-security.ts)

ExtractSymbolsDeps

type ExtractSymbolsDeps = BaseMcpToolDeps;

Defined in: packages/nexus-agents/src/mcp/tools/extract-symbols-tool.ts:89

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


GetJobResultDeps

type GetJobResultDeps = BaseMcpToolDeps;

Defined in: packages/nexus-agents/src/mcp/tools/get-job-result-tool.ts:85

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


GetJobResultInput

type GetJobResultInput = z.infer<typeof GetJobResultInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/get-job-result-tool.ts:44

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


ImprovementReviewDeps

type ImprovementReviewDeps = BaseMcpToolDeps;

Defined in: packages/nexus-agents/src/mcp/tools/improvement-review.ts:1002

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


ImprovementReviewInput

type ImprovementReviewInput = z.infer<typeof ImprovementReviewInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/improvement-review.ts:129

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


IssueTriageDeps

type IssueTriageDeps = BaseMcpToolDeps;

Defined in: packages/nexus-agents/src/mcp/tools/issue-triage-tool.ts:56

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


IssueTriageInput

type IssueTriageInput = z.infer<typeof IssueTriageInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/issue-triage-tool.ts:54

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


ListExpertsDeps

type ListExpertsDeps = BaseMcpToolDeps;

Defined in: packages/nexus-agents/src/mcp/tools/list-experts.ts:46

Dependencies for list_experts tool.


ListExpertsInput

type ListExpertsInput = z.infer<typeof ListExpertsInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/list-experts.ts:41

Type for validated list experts input.


ListJobsDeps

type ListJobsDeps = BaseMcpToolDeps;

Defined in: packages/nexus-agents/src/mcp/tools/list-jobs-tool.ts:109

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


ListJobsInput

type ListJobsInput = z.infer<typeof ListJobsInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/list-jobs-tool.ts:91

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


ListWorkflowsInput

type ListWorkflowsInput = z.infer<typeof ListWorkflowsInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/list-workflows.ts:43

Type for validated list workflows input.


McpLogLevel

type McpLogLevel = "debug" | "info" | "notice" | "warning" | "error";

Defined in: packages/nexus-agents/src/mcp/mcp-notifier.ts:25

Logging levels for MCP notifications (RFC 5424 syslog).


MemoryQueryInput

type MemoryQueryInput = z.infer<typeof MemoryQueryInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/memory-query.ts:63

Type for validated memory query input.


MemoryWriteInput

type MemoryWriteInput = z.infer<typeof MemoryWriteInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/memory-write.ts:73

Type for validated memory write input.


OrchestrateInput

type OrchestrateInput = z.infer<typeof OrchestrateInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/orchestrate-types.ts:87

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


OrchestrateOutput

type OrchestrateOutput = z.infer<typeof OrchestrateOutputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/orchestrate-types.ts:143

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


PolicyConfig

type PolicyConfig = z.infer<typeof PolicyConfigSchema>;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:152

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


PolicyMode

type PolicyMode = "enforce" | "warn";

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:42

Policy enforcement mode.

  • ‘enforce’: Block denied operations
  • ‘warn’: Log denials but allow execution (for migration)

PreferredCapability

type PreferredCapability = "reasoning" | "context" | "speed" | "code";

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:26

Preferred capability for task routing.


PrReviewDecision

type PrReviewDecision = "approve" | "request_changes" | "abstain";

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:227

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


PrReviewInput

type PrReviewInput = z.infer<typeof PrReviewInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:225

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


QueryTraceInput

type QueryTraceInput = z.infer<typeof QueryTraceInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/query-trace-tool.ts:47

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


RegistryImportInput

type RegistryImportInput = z.infer<typeof RegistryImportInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/registry-import-types.ts:32

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


RepoAnalyzeDeps

type RepoAnalyzeDeps = BaseMcpToolDeps;

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze-tool.ts:32

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


RepoAnalyzeInput

type RepoAnalyzeInput = z.infer<typeof RepoAnalyzeInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze-types.ts:40

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


RepoSecurityPlanDeps

type RepoSecurityPlanDeps = BaseMcpToolDeps;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-tool.ts:31

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


RepoSecurityPlanInput

type RepoSecurityPlanInput = z.infer<typeof RepoSecurityPlanInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:34

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


ResearchAddDeps

type ResearchAddDeps = BaseMcpToolDeps;

Defined in: packages/nexus-agents/src/mcp/tools/research-add.ts:63

Dependencies for research_add tool.


ResearchAddInput

type ResearchAddInput = z.infer<typeof ResearchAddInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/research-add.ts:54

Type for validated research add input.


ResearchAddSourceDeps

type ResearchAddSourceDeps = BaseMcpToolDeps;

Defined in: packages/nexus-agents/src/mcp/tools/research-add-source.ts:80

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


ResearchAddSourceInput

type ResearchAddSourceInput = z.infer<typeof ResearchAddSourceInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/research-add-source.ts:79

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


ResearchAnalyzeDeps

type ResearchAnalyzeDeps = BaseMcpToolDeps;

Defined in: packages/nexus-agents/src/mcp/tools/research-analyze.ts:58

Dependencies for research_analyze tool.


ResearchAnalyzeInput

type ResearchAnalyzeInput = z.infer<typeof ResearchAnalyzeInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/research-analyze.ts:49

Type for validated research analyze input.


ResearchCatalogReviewDeps

type ResearchCatalogReviewDeps = BaseMcpToolDeps;

Defined in: packages/nexus-agents/src/mcp/tools/research-catalog-review.ts:67

Dependencies for research_catalog_review tool.


ResearchDiscoverDeps

type ResearchDiscoverDeps = BaseMcpToolDeps;

Defined in: packages/nexus-agents/src/mcp/tools/research-discover.ts:168

Dependencies for research_discover tool.


ResearchDiscoverInput

type ResearchDiscoverInput = z.infer<typeof ResearchDiscoverInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/research-discover.ts:159

Type for validated research discover input.


ResearchQueryDeps

type ResearchQueryDeps = BaseMcpToolDeps;

Defined in: packages/nexus-agents/src/mcp/tools/research-query.ts:88

Dependencies for research_query tool.


ResearchQueryInput

type ResearchQueryInput = z.infer<typeof ResearchQueryInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/research-query.ts:64

Type for validated research query input.


ResearchSynthesizeDeps

type ResearchSynthesizeDeps = BaseMcpToolDeps;

Defined in: packages/nexus-agents/src/mcp/tools/research-synthesize.ts:48

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


ResearchSynthesizeInput

type ResearchSynthesizeInput = z.infer<typeof ResearchSynthesizeInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/research-synthesize.ts:42

Type for validated research synthesize input.


RunGraphWorkflowInput

type RunGraphWorkflowInput = z.infer<typeof RunGraphWorkflowInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow.ts:82

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


RunWorkflowInput

type RunWorkflowInput = z.infer<typeof RunWorkflowInputSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:102

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


SearchCodebaseDeps

type SearchCodebaseDeps = BaseMcpToolDeps;

Defined in: packages/nexus-agents/src/mcp/tools/search-codebase-tool.ts:60

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


SearchUsagesDeps

type SearchUsagesDeps = BaseMcpToolDeps;

Defined in: packages/nexus-agents/src/mcp/tools/search-usages-tool.ts:119

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


VoteDecisionStatus

type VoteDecisionStatus = z.infer<typeof VoteDecisionStatusSchema>;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:415

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


CancelJobInputSchema

const CancelJobInputSchema: ZodObject<{
  jobId: ZodString;
  reason: ZodOptional<ZodString>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/cancel-job-tool.ts:56

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


ConsensusVoteInputSchema

const ConsensusVoteInputSchema: ZodObject<{
  dispatch: ZodOptional<DispatchEnum>;
  errorPolicy: ZodOptional<ZodEnum<{
     absolute_quorum: "absolute_quorum";
     count_as_abstain: "count_as_abstain";
     fail_closed: "fail_closed";
     reduce_denominator: "reduce_denominator";
  }>>;
  idempotencyKey: ZodOptional<ZodString>;
  mode: ZodOptional<ZodEnum<{
     async: "async";
     sync: "sync";
  }>>;
  options: ZodOptional<ZodArray<ZodString>>;
  project: ZodOptional<ZodString>;
  proposal: ZodString;
  quickMode: ZodDefault<ZodOptional<ZodBoolean>>;
  ratifies: ZodOptional<ZodString>;
  ratifiesPr: ZodOptional<ZodObject<{
     headSha: ZodString;
     pr: ZodNumber;
  }, $strict>>;
  simulateVotes: ZodDefault<ZodOptional<ZodBoolean>>;
  strategy: ZodOptional<ZodEnum<{
     higher_order: "higher_order";
     opinion_wise: "opinion_wise";
     proof_of_learning: "proof_of_learning";
     simple_majority: "simple_majority";
     supermajority: "supermajority";
     unanimous: "unanimous";
  }>>;
  threshold: ZodOptional<ZodEnum<{
     majority: "majority";
     supermajority: "supermajority";
     unanimous: "unanimous";
  }>>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/consensus-vote-types.ts:204

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


CreateExpertInputSchema

const CreateExpertInputSchema: ZodObject<{
  modelPreference: ZodOptional<ZodString>;
  role: ZodEnum<{
     architecture_expert: "architecture_expert";
     code_expert: "code_expert";
     data_visualization_expert: "data_visualization_expert";
     devops_expert: "devops_expert";
     documentation_expert: "documentation_expert";
     infrastructure_expert: "infrastructure_expert";
     pm_expert: "pm_expert";
     qa_expert: "qa_expert";
     research_expert: "research_expert";
     security_expert: "security_expert";
     testing_expert: "testing_expert";
     ux_expert: "ux_expert";
  }>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/create-expert.ts:75

Input schema for create_expert tool.


DelegateInputSchema

const DelegateInputSchema: ZodObject<{
  billing_mode: ZodOptional<ZodEnum<{
     api: "api";
     plan: "plan";
  }>>;
  model_hint: ZodOptional<ZodString>;
  preferred_capability: ZodOptional<ZodEnum<{
     code: "code";
     context: "context";
     reasoning: "reasoning";
     speed: "speed";
  }>>;
  task: ZodString;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:56

Input schema for the delegate_to_model tool.


DelegateOutputSchema

const DelegateOutputSchema: ZodObject<{
  alternatives: ZodArray<ZodObject<{
     model: ZodString;
     score: ZodNumber;
     tradeoff: ZodString;
  }, $strip>>;
  capabilities: ZodObject<{
     codeGeneration: ZodNumber;
     contextWindow: ZodNumber;
     cost: ZodNumber;
     reasoning: ZodNumber;
     speed: ZodNumber;
  }, $strip>;
  estimated_tokens: ZodNumber;
  governance: ZodOptional<ZodObject<{
     domain: ZodString;
     promotionReason: ZodString;
     votingThreshold: ZodString;
  }, $strip>>;
  reasoning: ZodString;
  recommended_model: ZodString;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:84

Output schema for the delegate_to_model tool response.


denyMutationsWithoutModeRule

const denyMutationsWithoutModeRule: FirewallPolicyRule;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-rules.ts:92

Policy rule that denies mutation operations when mode is ‘read-only’.

This ensures that write operations are only allowed when explicitly enabled via the ‘read-write’ mode. Two inputs: ctx.mode is the permission the operator granted; the tool’s class comes from the manifest (#5114). An unclassified tool is denied too, but the verdict SAYS it was unclassified — a rollout needs to tell “a write the mode forbids” from “nobody classified this”, and a boolean cannot.


ExecuteExpertInputSchema

const ExecuteExpertInputSchema: ZodObject<{
  context: ZodOptional<ZodRecord<ZodString, ZodUnknown>>;
  expertId: ZodString;
  previousExpertSummary: ZodOptional<ZodString>;
  task: ZodString;
  timeoutMs: ZodOptional<ZodNumber>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/execute-expert.ts:74

Input schema for execute_expert tool.


ExecuteSpecInputSchema

const ExecuteSpecInputSchema: ZodObject<{
  dispatch: ZodDefault<DispatchEnum>;
  dryRun: ZodDefault<ZodOptional<ZodBoolean>>;
  mode: RejectedModeKey;
  spec: ZodString;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/execute-spec-tool.ts:48

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


ExtractSymbolsInputSchema

const ExtractSymbolsInputSchema: ZodObject<{
  filePath: ZodString;
  maxChars: ZodOptional<ZodNumber>;
  maxSymbols: ZodOptional<ZodNumber>;
  mode: ZodOptional<ZodEnum<{
     full: "full";
     index: "index";
  }>>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/extract-symbols-tool.ts:53

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


FALLBACK_SCANNER_DATA

const FALLBACK_SCANNER_DATA: ScannerData;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-fallback.ts:310

Embedded scanner data snapshot used when live registry is unavailable.


GetJobResultInputSchema

const GetJobResultInputSchema: ZodObject<{
  jobId: ZodString;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/get-job-result-tool.ts:39

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


ImprovementReviewInputSchema

const ImprovementReviewInputSchema: ZodObject<{
  fileIssues: ZodDefault<ZodOptional<ZodBoolean>>;
  fitnessFloor: ZodDefault<ZodOptional<ZodNumber>>;
  lookbackDays: ZodDefault<ZodOptional<ZodNumber>>;
  minSampleSize: ZodDefault<ZodOptional<ZodNumber>>;
  selfEvalReportPath: ZodOptional<ZodString>;
  targetRepo: ZodOptional<ZodString>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/improvement-review.ts:78

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


IssueTriageInputSchema

const IssueTriageInputSchema: ZodObject<{
  dryRun: ZodDefault<ZodOptional<ZodBoolean>>;
  issueUrl: ZodString;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/issue-triage-tool.ts:41

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


ListExpertsInputSchema

const ListExpertsInputSchema: ZodObject<{
  format: ZodDefault<ZodOptional<ZodEnum<{
     full: "full";
     names: "names";
  }>>>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/list-experts.ts:30

Input schema for list_experts tool. Currently no parameters required (lists all experts).


ListJobsInputSchema

const ListJobsInputSchema: ZodObject<{
  abandoned: ZodOptional<ZodBoolean>;
  limit: ZodOptional<ZodNumber>;
  status: ZodOptional<ZodEnum<{
     cancelled: "cancelled";
     complete: "complete";
     failed: "failed";
     pending: "pending";
  }>>;
  toolName: ZodOptional<ZodString>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/list-jobs-tool.ts:60

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


ListWorkflowsInputSchema

const ListWorkflowsInputSchema: ZodObject<{
  category: ZodOptional<ZodString>;
  format: ZodDefault<ZodOptional<ZodEnum<{
     full: "full";
     names: "names";
  }>>>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/list-workflows.ts:31

Input schema for list_workflows tool.


MAX_DIFF_LENGTH

const MAX_DIFF_LENGTH: 50000 = 50_000;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:95

The BINDING cap, mirrored: the UTF-8 byte cap the canonical reviewedDiffHash binds to (MAX_REVIEWED_DIFF_BYTES, #3831). Since #6003 this is NOT the panel budget: what the 5-voter panel reads is bounded by the voters’ context windows (pr-review-panel-budget.ts), and this cap is only the panel budget when that derivation fails closed. A diff over this cap is never rejected; the record states that the hash binds a prefix. Still the local-ledger script’s diff cap.


MemoryQueryInputSchema

const MemoryQueryInputSchema: ZodObject<{
  limit: ZodDefault<ZodOptional<ZodNumber>>;
  query: ZodString;
  source: ZodDefault<ZodOptional<ZodEnum<{
     adaptive: "adaptive";
     agentic: "agentic";
     all: "all";
     belief: "belief";
     session: "session";
     typed: "typed";
  }>>>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/memory-query.ts:43

Input schema for memory_query tool.


MemoryStatsInputSchema

const MemoryStatsInputSchema: ZodObject<{
  includeDecay: ZodDefault<ZodOptional<ZodBoolean>>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/memory-stats.ts:36

Input schema for memory_stats tool.


MemoryWriteInputSchema

const MemoryWriteInputSchema: ZodObject<{
  backend: ZodEnum<{
     adaptive: "adaptive";
     agentic: "agentic";
     belief: "belief";
     session: "session";
     typed: "typed";
  }>;
  confidence: ZodDefault<ZodOptional<ZodEnum<{
     high: "high";
     low: "low";
     medium: "medium";
  }>>>;
  content: ZodString;
  key: ZodString;
  metadata: ZodOptional<ZodRecord<ZodString, ZodString>>;
  sourceTrustTier: ZodOptional<ZodEnum<{
     1: "1";
     2: "2";
     3: "3";
     4: "4";
  }>>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/memory-write.ts:49

Input schema for memory_write tool.


MODEL_CAPABILITIES

const MODEL_CAPABILITIES: Record<string, CapabilityProfile>;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-types.ts:51

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


NOOP_NOTIFIER

const NOOP_NOTIFIER: IMcpNotifier;

Defined in: packages/nexus-agents/src/mcp/mcp-notifier.ts:82

No-op notifier for when MCP server is not available.


OrchestrateInputSchema

const OrchestrateInputSchema: ZodObject<{
  context: ZodOptional<ZodRecord<ZodString, ZodUnknown>>;
  dispatch: ZodOptional<DispatchEnum>;
  idempotencyKey: ZodOptional<ZodString>;
  maxIterations: ZodDefault<ZodOptional<ZodNumber>>;
  mode: ZodOptional<ZodEnum<{
     async: "async";
     sync: "sync";
  }>>;
  task: ZodString;
  timeout: ZodOptional<ZodNumber>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/orchestrate-types.ts:27

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


OrchestrateOutputSchema

const OrchestrateOutputSchema: ZodObject<{
  analysis: ZodObject<{
     approach: ZodString;
     complexity: ZodNumber;
     estimatedEffort: ZodNumber;
     needsDecomposition: ZodBoolean;
     requirements: ZodArray<ZodString>;
     risks: ZodArray<ZodString>;
     taskId: ZodString;
     taskType: ZodString;
  }, $strip>;
  metadata: ZodObject<{
     durationMs: ZodNumber;
     expertsUsed: ZodArray<ZodString>;
     timeoutReason: ZodOptional<ZodString>;
     tokensMeasured: ZodOptional<ZodBoolean>;
     tokensUsed: ZodNumber;
  }, $strip>;
  result: ZodUnknown;
  routing: ZodOptional<ZodObject<{
     confidence: ZodNumber;
     orchestratorType: ZodString;
     pattern: ZodString;
     reasoning: ZodString;
  }, $strip>>;
  stepsCompleted: ZodNumber;
  taskId: ZodString;
  workerDispatchStatus: ZodOptional<ZodEnum<{
     failed: "failed";
     partial: "partial";
     success: "success";
  }>>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/orchestrate-types.ts:89

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


PolicyConfigSchema

const PolicyConfigSchema: ZodObject<{
  allowedPaths: ZodDefault<ZodArray<ZodString>>;
  defaultMode: ZodDefault<ZodEnum<{
     read-only: "read-only";
     read-write: "read-write";
  }>>;
  policyMode: ZodDefault<ZodEnum<{
     enforce: "enforce";
     warn: "warn";
  }>>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-types.ts:146

Schema for policy configuration. Same default as config/schemas-security.ts — one constant, not two (#6431).


PR_REVIEW_ROLES

const PR_REVIEW_ROLES: readonly VoterRole[];

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:81

Voter panel for PR review. PM and AI/ML excluded — they’re proposal-level roles, not code-level. The 5 here are the ones with concrete claims about code (#2233).


PROMPT_DEFINITIONS

const PROMPT_DEFINITIONS: readonly PromptDefinition[];

Defined in: packages/nexus-agents/src/mcp/prompts/prompt-definitions.ts:155

All registered MCP prompt templates.

Each entry provides a Zod args schema for validation and a message builder.


PrReviewInputSchema

const PrReviewInputSchema: ZodObject<{
  baseRef: ZodOptional<ZodString>;
  baseSha: ZodOptional<ZodString>;
  dispatch: ZodDefault<DispatchEnum>;
  errorPolicy: ZodDefault<ZodEnum<{
     absolute_quorum: "absolute_quorum";
     standard: "standard";
  }>>;
  headRef: ZodOptional<ZodString>;
  mode: RejectedModeKey;
  prDescription: ZodOptional<ZodString>;
  prDiff: ZodString;
  prNumber: ZodOptional<ZodNumber>;
  project: ZodOptional<ZodString>;
  prTitle: ZodString;
  repoContext: ZodOptional<ZodString>;
  repoPath: ZodOptional<ZodString>;
  simulate: ZodDefault<ZodBoolean>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:123

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


QueryTraceInputSchema

const QueryTraceInputSchema: ZodObject<{
  eventType: ZodOptional<ZodString>;
  limit: ZodOptional<ZodNumber>;
  runId: ZodString;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/query-trace-tool.ts:31

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


RegistryImportInputSchema

const RegistryImportInputSchema: ZodObject<{
  dryRun: ZodDefault<ZodOptional<ZodBoolean>>;
  modelId: ZodString;
  provider: ZodEnum<{
     anthropic: "anthropic";
     google: "google";
     openai: "openai";
  }>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/registry-import-types.ts:17

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


RepoAnalyzeInputSchema

const RepoAnalyzeInputSchema: ZodObject<{
  depth: ZodDefault<ZodOptional<ZodEnum<{
     deep: "deep";
     shallow: "shallow";
  }>>>;
  repo: ZodString;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze-types.ts:16

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


RepoSecurityPlanInputSchema

const RepoSecurityPlanInputSchema: ZodObject<{
  categories: ZodOptional<ZodArray<ZodString>>;
  maxScanners: ZodDefault<ZodOptional<ZodNumber>>;
  repo: ZodString;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan-types.ts:16

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


ResearchAddInputSchema

const ResearchAddInputSchema: ZodObject<{
  arxivId: ZodString;
  dryRun: ZodDefault<ZodOptional<ZodBoolean>>;
  priority: ZodOptional<ZodEnum<{
     P1: "P1";
     P2: "P2";
     P3: "P3";
     P4: "P4";
  }>>;
  topic: ZodOptional<ZodString>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/research-add.ts:37

Input schema for research_add tool.


ResearchAddSourceInputSchema

const ResearchAddSourceInputSchema: ZodObject<{
  dryRun: ZodDefault<ZodOptional<ZodBoolean>>;
  name: ZodString;
  quality_signals: ZodOptional<ZodObject<{
     has_docs: ZodOptional<ZodBoolean>;
     has_paper: ZodOptional<ZodBoolean>;
     has_tests: ZodOptional<ZodBoolean>;
     language: ZodOptional<ZodString>;
     stars_at_review: ZodOptional<ZodNumber>;
  }, $strip>>;
  tags: ZodOptional<ZodArray<ZodString>>;
  techniques_extracted: ZodOptional<ZodArray<ZodString>>;
  topics: ZodOptional<ZodArray<ZodString>>;
  type: ZodEnum<{
     code_analysis: "code_analysis";
     open_source_repo: "open_source_repo";
     product_docs: "product_docs";
     research_blog: "research_blog";
     specification: "specification";
  }>;
  url: ZodString;
  vendor: ZodOptional<ZodString>;
  verdict: ZodOptional<ZodEnum<{
     adopted: "adopted";
     monitoring: "monitoring";
     partially_adopted: "partially_adopted";
     planned: "planned";
     rejected: "rejected";
  }>>;
  verdict_notes: ZodOptional<ZodString>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/research-add-source.ts:52

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


ResearchAnalyzeInputSchema

const ResearchAnalyzeInputSchema: ZodObject<{
  focus: ZodEnum<{
     coverage: "coverage";
     gaps: "gaps";
     priorities: "priorities";
     stale: "stale";
     trends: "trends";
  }>;
  topic: ZodOptional<ZodString>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/research-analyze.ts:37

Input schema for research_analyze tool.


ResearchCatalogReviewInputSchema

const ResearchCatalogReviewInputSchema: ZodObject<{
  action: ZodEnum<{
     approve: "approve";
     dismiss: "dismiss";
     flush: "flush";
     list: "list";
  }>;
  createIssue: ZodDefault<ZodOptional<ZodBoolean>>;
  identifier: ZodOptional<ZodString>;
  topic: ZodOptional<ZodString>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/research-catalog-review.ts:37

Input schema for research_catalog_review tool.


ResearchDiscoverInputSchema

const ResearchDiscoverInputSchema: ZodObject<{
  maxResults: ZodDefault<ZodOptional<ZodNumber>>;
  relevanceThreshold: ZodDefault<ZodOptional<ZodNumber>>;
  sinceDate: ZodOptional<ZodString>;
  source: ZodDefault<ZodOptional<ZodEnum<{
     all: "all";
     arxiv: "arxiv";
     deepmind: "deepmind";
     github: "github";
     google_ai: "google_ai";
     meta_fair: "meta_fair";
     microsoft: "microsoft";
     openalex: "openalex";
     papers_with_code: "papers_with_code";
     semantic_scholar: "semantic_scholar";
  }>>>;
  topic: ZodString;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/research-discover.ts:110

Input schema for research_discover tool.


ResearchQueryInputSchema

const ResearchQueryInputSchema: ZodObject<{
  action: ZodEnum<{
     overlap: "overlap";
     search: "search";
     stats: "stats";
     status: "status";
  }>;
  query: ZodOptional<ZodString>;
  status: ZodDefault<ZodOptional<ZodEnum<{
     all: "all";
     implemented: "implemented";
     not-started: "not-started";
     planned: "planned";
     rejected: "rejected";
  }>>>;
  techniqueId: ZodOptional<ZodString>;
  threshold: ZodDefault<ZodOptional<ZodNumber>>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/research-query.ts:39

Input schema for research_query tool.


ResearchSynthesizeInputSchema

const ResearchSynthesizeInputSchema: ZodObject<{
  topic: ZodOptional<ZodString>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/research-synthesize.ts:35

Input schema for research_synthesize tool.


RunGraphWorkflowInputSchema

const RunGraphWorkflowInputSchema: ZodObject<{
  dispatch: ZodDefault<DispatchEnum>;
  enableAuditTrail: ZodDefault<ZodOptional<ZodBoolean>>;
  enableCheckpointing: ZodDefault<ZodOptional<ZodBoolean>>;
  inputs: ZodDefault<ZodOptional<ZodRecord<ZodString, ZodUnknown>>>;
  mode: RejectedModeKey;
  workflow: ZodString;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow.ts:55

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


RunWorkflowInputSchema

const RunWorkflowInputSchema: ZodObject<{
  dispatch: ZodOptional<DispatchEnum>;
  dryRun: ZodDefault<ZodOptional<ZodBoolean>>;
  idempotencyKey: ZodOptional<ZodString>;
  inputs: ZodRecord<ZodString, ZodUnknown>;
  maxTokens: ZodOptional<ZodNumber>;
  mode: ZodOptional<ZodEnum<{
     async: "async";
     sync: "sync";
  }>>;
  template: ZodString;
  timeoutMs: ZodOptional<ZodNumber>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/run-workflow-types.ts:25

Input schema for the run_workflow tool.


safePathsRule

const safePathsRule: FirewallPolicyRule;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-rules.ts:124

Policy rule that validates paths against allowed roots.

Prevents path traversal attacks by ensuring all file operations target paths within configured allowed directories.


SearchCodebaseInputSchema

const SearchCodebaseInputSchema: ZodObject<{
  directory: ZodOptional<ZodString>;
  limit: ZodOptional<ZodNumber>;
  maxDepth: ZodOptional<ZodNumber>;
  mode: ZodOptional<ZodEnum<{
     list: "list";
     search: "search";
     summary: "summary";
  }>>;
  query: ZodString;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/search-codebase-tool.ts:35

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


SearchUsagesInputSchema

const SearchUsagesInputSchema: ZodObject<{
  dir: ZodOptional<ZodString>;
  lang: ZodOptional<ZodEnum<{
     javascript: "javascript";
     tsx: "tsx";
     typescript: "typescript";
  }>>;
  limit: ZodOptional<ZodNumber>;
  maxDepth: ZodOptional<ZodNumber>;
  path: ZodOptional<ZodString>;
  symbol: ZodString;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/search-usages-tool.ts:75

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


secretPathsRule

const secretPathsRule: FirewallPolicyRule;

Defined in: packages/nexus-agents/src/mcp/middleware/policy-rules.ts:175

Policy rule that denies access to secret-bearing paths (SSH keys, cloud credentials, .env, /etc/shadow, …) whatever allowedPaths says.

Composes AND-deny with safePathsRule: that rule is containment against the allowlist, this one is a denylist inside it. A caller who widens allowedPaths to $HOME keeps ~/.ssh closed, and .env inside the repo root is refused even though it passes containment. No path argument → the rule abstains (an allow with that reason), because absence of a path is not a file operation and must not be recorded as “no secret”.


WeatherReportInputSchema

const WeatherReportInputSchema: ZodObject<{
  category: ZodOptional<ZodEnum<{
     architecture: "architecture";
     code_generation: "code_generation";
     code_review: "code_review";
     devops: "devops";
     documentation: "documentation";
     exploration: "exploration";
     planning: "planning";
     research: "research";
     security_review: "security_review";
     testing: "testing";
  }>>;
  cli: ZodOptional<ZodEnum<{
     claude: "claude";
     codex: "codex";
     gemini: "gemini";
     opencode: "opencode";
  }>>;
  includeAdaptive: ZodDefault<ZodOptional<ZodBoolean>>;
}, $strip>;

Defined in: packages/nexus-agents/src/mcp/tools/weather-report-types.ts:23

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports


aggregatePrDecisions()

function aggregatePrDecisions(reviews, errorPolicy?): PrReviewAggregate;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:358

Aggregates per-voter decisions into a single summary outcome with a verified/unverified tag (#2250 Child 7).

Tiers, in order:

  1. Verified blocker (request_changes, verified=true) — at least one non-error voter declared request_changes AND has at least one VERIFIED finding (all 4 gate checks passed with substantive named_assertion). This is the #2225 verification gate.
  2. Soft blocker (request_changes, verified=false) — ≥3 of 5 non-error voters voted request_changes, but none produced a verified finding. The retest in #2241 showed voters reliably flag diff-readable bugs at this rate even without producing the YAML structure (#2245 covers why). Tagged unverified so reviewers apply the verification gate themselves.
  3. Approve (verified=true) — all non-error voters approve.
  4. Abstain (verified=true) — anything else; conservative default.

Why no “AND has any finding” guard on the soft path: the empirical data in pr-review-experiment-results-v2.md showed voters voting request_changes but emitting 0 findings (verified or otherwise). Adding the finding requirement would zero this path out and reproduce the baseline behavior.

Parameters

reviews

readonly PrReviewVote[]

errorPolicy?

"standard" | "absolute_quorum"

Returns

PrReviewAggregate


analyzeDelegateTask()

function analyzeDelegateTask(task): TaskRequirements;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-helpers.ts:57

Analyzes a task string to determine requirements.

Parameters

task

string

Returns

TaskRequirements


analyzeGitHubRepo()

function analyzeGitHubRepo(input, execOverride?): Promise<RepoAnalysis>;

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze.ts:760

Fetch repo data from GitHub and produce analysis.

Parameters

input
depth

"deep" | "shallow" = ...

Currently a no-op: the handler ignores this flag and always runs the full analysis. Both values resolve to identical behavior; retained for input-shape stability until a distinct shallow path is implemented.

repo

string = ...

GitHub repository in “owner/name” format or full URL.

execOverride?

ExecFileFn

Injected gh runner, so the FETCH path is testable and not only the pure functions downstream of it (#6035).

Without this, reverting fetchWorkflowEntries to report listed: true on error broke no test: the flag was exercised by injecting it into identifyGaps directly, while the producer that derives it had no coverage at all. Every other fetch in this module already takes an ExecFileFn; the entry point was the one place that did not.

Returns

Promise<RepoAnalysis>


analyzeRepo()

function analyzeRepo(
   metadata, 
   topLevelEntries, 
   workflowEntries?, 
   listings?
): RepoAnalysis;

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze.ts:444

Analyze a GitHub repository given its metadata and file tree.

Parameters

metadata

GhRepoMetadata

topLevelEntries

readonly string[]

workflowEntries?

readonly string[]

listings?

RepoListings = {}

What each secondary listing observed — grouped, not four positional flags.

Returns

RepoAnalysis


buildPlanFromAnalysis()

function buildPlanFromAnalysis(
   analysis, 
   input, 
   data?
): RepoSecurityPlan;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan.ts:462

Pure function: build plan from analysis + scanner data (testable).

Parameters

analysis

RepoAnalysis

input

BuildPlanOptions

data?

ScannerData

Returns

RepoSecurityPlan


buildPrReviewProposal()

function buildPrReviewProposal(input, removedBefore?): string;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-proposal.ts:124

Builds the proposal text passed to voters. The voters are designed for yes/no proposals — by framing the diff as “should this PR be merged?” we get usable output without needing new system prompts (Child 3 will add those).

Sanitization lives HERE, not at the tool boundary (#5258 item B). The securityTier: 'external' declared on the registered tool only protects the MCP path, because the middleware is constructed inside registerPrReviewTool. Three other callers reach the voters without it — .github/workflows/ pr-review.yml, scripts/pr-review-local.ts (the documented default path) and scripts/pr-review-eval-run.ts — each importing this builder directly from dist/index.js. On those paths a hostile PR body reached five voters unfenced, next to the words “should it be merged as-is?”.

This function is the one chokepoint all four callers pass through, so the protection is attached to the data rather than to one entry point. The MCP tier check still runs earlier and still refuses; this is the floor beneath it, and it strips rather than refuses so the script paths degrade instead of failing shut. Double-sanitizing on the MCP path is idempotent and harmless.

Parameters

input

Pick<PrReviewInput, | "prTitle" | "prDescription" | "prDiff" | "repoContext" | "baseRef" | "headRef">

removedBefore?

What an EARLIER sanitization stage already removed (#5385). Both counts are needed because the sanitizer strips two different things through two different counters — comments alone cannot represent a tag strip, and a note that says “nothing was removed” about a stripped injection tag is worse than no note. Defaults to zeroes for the CI and script paths, where nothing runs before this call.

comments

number

fields

number

tags

number

Returns

string


clearRegistryCache()

function clearRegistryCache(): void;

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:106

Clear the cache and inflight state (for testing).

Returns

void


closeServer()

function closeServer(server, logger?): Promise<Result<void, ServerError>>;

Defined in: packages/nexus-agents/src/mcp/server.ts:260

Gracefully closes the server connection.

Parameters

server

McpServer

The MCP server to close

logger?

ILogger

Optional logger

Returns

Promise<Result<void, ServerError>>

Result indicating success or failure


connectTransport()

function connectTransport(
   server, 
   transport, 
   logger?
): Promise<Result<void, ServerError>>;

Defined in: packages/nexus-agents/src/mcp/server.ts:157

Connects the server to a transport.

Parameters

server

McpServer

The MCP server instance

transport

Transport

The transport to connect to

logger?

ILogger

Logger for the operation

Returns

Promise<Result<void, ServerError>>

Result indicating success or failure


createDefaultDeps()

function createDefaultDeps(rateLimiter, logger?): CreateExpertDeps;

Defined in: packages/nexus-agents/src/mcp/tools/create-expert.ts:363

Creates default dependencies for the create_expert tool.

Parameters

rateLimiter

McpRateLimiter

Rate limiter for throttling tool calls (required)

logger?

ILogger

Optional logger instance

Returns

CreateExpertDeps

CreateExpertDeps with default factory and empty registry


createDefaultPolicyFirewall()

function createDefaultPolicyFirewall(config?): PolicyFirewall;

Defined in: packages/nexus-agents/src/mcp/middleware/policy.ts:259

Creates a policy firewall with default rules.

Default rules included, in evaluation order:

  • deny-mutations-without-mode
  • secret-paths (#5108) — ahead of safe-paths so a secret is reported as a secret, not as a .. or an out-of-root path
  • safe-paths

Parameters

config?

PolicyFirewallConfig

Optional configuration

Returns

PolicyFirewall

A configured PolicyFirewall instance


createDefaultRateLimiter()

function createDefaultRateLimiter(name?, logger?): McpRateLimiter;

Defined in: packages/nexus-agents/src/mcp/middleware/rate-limiter.ts:179

Creates a rate limiter with default settings suitable for MCP tools.

Default configuration:

  • Capacity: 100 tokens
  • Refill rate: 10 tokens per second

Parameters

name?

string

Optional name for the rate limiter

logger?

ILogger

Optional logger instance

Returns

McpRateLimiter

A configured RateLimiter instance


createMcpLogger()

function createMcpLogger(baseContext?): ILogger;

Defined in: packages/nexus-agents/src/mcp/middleware/logging.ts:38

Creates a logger with MCP-specific context.

Parameters

baseContext?

McpLogContext

Base context to include in all log entries

Returns

ILogger

An ILogger instance with MCP context

Example

const logger = createMcpLogger({ requestId: 'req-123' });
logger.info('Processing request', { tool: 'orchestrate' });

createMcpNotifier()

function createMcpNotifier(server): IMcpNotifier;

Defined in: packages/nexus-agents/src/mcp/mcp-notifier.ts:47

Creates an MCP notifier that sends logging notifications to connected clients.

Notifications are fire-and-forget — failures are logged but never propagate to callers. This ensures observability never breaks tool execution.

Parameters

server

McpServer

Returns

IMcpNotifier


createPolicyContext()

function createPolicyContext(
   toolName, 
   args, 
   options?
): FirewallPolicyContext;

Defined in: packages/nexus-agents/src/mcp/middleware/policy.ts:311

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports

Parameters

toolName

string

args

unknown

options?
allowedPaths?

readonly string[]

artifacts?

Map<string, FirewallArtifact<unknown>>

mode?

ExecutionMode

workflowId?

string

Returns

FirewallPolicyContext


createServer()

function createServer(config?): Result<ServerInstance, ServerError>;

Defined in: packages/nexus-agents/src/mcp/server.ts:93

Creates a new MCP server instance.

Parameters

config?

ServerConfig

Optional server configuration

Returns

Result<ServerInstance, ServerError>

Result containing the server instance or an error

Example

const result = createServer({ name: 'my-server' });
if (result.ok) {
  const { server, logger } = result.value;
  // Register tools on server
}

createTimer()

function createTimer(): {
  elapsed: () => number;
};

Defined in: packages/nexus-agents/src/mcp/middleware/logging.ts:144

Creates a timing utility for measuring operation duration.

Returns

{
  elapsed: () => number;
}

An object with start time and elapsed() method

elapsed
elapsed: () => number;
Returns

number

Example

const timer = createTimer();
// ... perform operation
const durationMs = timer.elapsed();

createToolLogger()

function createToolLogger(
   parentLogger, 
   toolName, 
   requestId?
): ILogger;

Defined in: packages/nexus-agents/src/mcp/middleware/logging.ts:53

Creates a child logger for a specific tool execution.

Parameters

parentLogger

ILogger

The parent logger instance

toolName

string

Name of the tool being executed

requestId?

string

Optional request ID for tracing

Returns

ILogger

A child logger with tool context


createValidator()

function createValidator<T>(schema): (args) => Result<T, ValidationError>;

Defined in: packages/nexus-agents/src/mcp/middleware/validation.ts:83

Creates a validation function bound to a specific schema.

Useful for reusing the same schema across multiple tools.

Type Parameters

T

T

The expected type after validation

Parameters

schema

ZodType<T>

The Zod schema to bind

Returns

A validation function for the schema

(args) => Result<T, ValidationError>

Example

const validateTask = createValidator(TaskSchema);

// Later in tool handlers:
const result = validateTask(args);

evaluatePolicy()

function evaluatePolicy(firewall, ctx): Result<void, PolicyError>;

Defined in: packages/nexus-agents/src/mcp/middleware/policy.ts:280

Evaluates a policy context and returns a Result.

This is a convenience function that wraps the firewall evaluation in a Result type for easier error handling.

Parameters

firewall

IPolicyFirewall

The policy firewall to use

ctx

FirewallPolicyContext

The policy context to evaluate

Returns

Result<void, PolicyError>

Result containing void on success or PolicyError on denial


generateSecurityPlan()

function generateSecurityPlan(input): Promise<RepoSecurityPlan>;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan.ts:409

Generate a security scanning plan for a repository (fetches live data).

Parameters

input
categories?

string[] = ...

Filter to specific scanner categories.

maxScanners

number = ...

Maximum number of scanners to recommend.

repo

string = ...

GitHub repository in “owner/name” format or full URL.

Returns

Promise<RepoSecurityPlan>


generateWeatherReport()

function generateWeatherReport(
   input, 
   config?, 
   deps?
): WeatherReportResponse;

Defined in: packages/nexus-agents/src/mcp/tools/weather-report.ts:129

Generates the weather report from current outcome data.

Parameters

input

WeatherReportOptions

config?

Partial<{ coldStartThreshold: number; explorationRate: number; maxBonusAdjustment: number; outcomeLookbackMs: number; }>

deps?

WeatherReportDeps

Returns

WeatherReportResponse


getAvailableRoles()

function getAvailableRoles(): string[];

Defined in: packages/nexus-agents/src/mcp/tools/create-expert.ts:375

Gets the list of available expert roles.

Returns

string[]


getCapabilitiesForRole()

function getCapabilitiesForRole(role): readonly AgentCapability[] | undefined;

Defined in: packages/nexus-agents/src/mcp/tools/create-expert.ts:382

Gets capabilities for a given expert role.

Parameters

role

string

Returns

readonly AgentCapability[] | undefined


getEventBusStats()

function getEventBusStats(): {
  activeSubscriptions: number;
  errorCount: number;
  eventsEmitted: number;
  historySize: number;
};

Defined in: packages/nexus-agents/src/mcp/eventbus-bridge.ts:291

Gets CollaborationEventBus statistics for observability reporting.

Returns

{
  activeSubscriptions: number;
  errorCount: number;
  eventsEmitted: number;
  historySize: number;
}
activeSubscriptions
activeSubscriptions: number;
errorCount
errorCount: number;
eventsEmitted
eventsEmitted: number;
historySize
historySize: number;

getGraphRegistry()

function getGraphRegistry(): ReadonlyMap<string, GraphFactory>;

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow-templates.ts:92

Registry of all predefined graph workflows (built-in + heuristic “multi-CLI” templates + security setup).

Returns

ReadonlyMap<string, GraphFactory>


getGraphWorkflowList()

function getGraphWorkflowList(): readonly GraphWorkflowInfo[];

Defined in: packages/nexus-agents/src/mcp/tools/run-graph-workflow-templates.ts:83

Returns metadata about all available graph workflows (built-in + heuristic “multi-CLI” templates + security setup).

Returns

readonly GraphWorkflowInfo[]


getRegistryManifest()

function getRegistryManifest(): Promise<ScannerRegistryManifest | null>;

Defined in: packages/nexus-agents/src/mcp/tools/scanner-registry-fetcher.ts:237

Get the scanner registry, fetching from GitHub if cache is stale. Returns null if no cached data and fetch fails.

Returns

Promise<ScannerRegistryManifest | null>


initializeEventBusBridge()

function initializeEventBusBridge(
   observer, 
   logger, 
   config?
): EventBusBridgeResult;

Defined in: packages/nexus-agents/src/mcp/eventbus-bridge.ts:161

Initializes the CollaborationEventBus bridge with SwarmObserver integration.

Subscribes to configured event patterns and:

  1. Logs events at appropriate levels (debug for frequent, info for important)
  2. Records interactions to SwarmObserver for graph-based analysis
  3. Tracks event statistics for observability

Parameters

observer

InteractionSwarmObserver

SwarmObserver instance for interaction tracking

logger

ILogger

Logger instance for event logging

config?

Partial<{ enabled: boolean; logging: { frequentEventLevel: "debug" | "info"; importantEventLevel: "debug" | "info"; }; maxHistorySize: number; subscriptions: { agent: boolean; byzantine: boolean; consensus: boolean; message: boolean; protocol: boolean; session: boolean; }; }>

Optional CollaborationEventBus configuration

Returns

EventBusBridgeResult

Bridge result with cleanup function


isZodError()

function isZodError(error): error is ZodError<unknown>;

Defined in: packages/nexus-agents/src/core/zod-helpers.ts:97

Type guard to check if a value is a Zod error.

Parameters

error

unknown

The value to check

Returns

error is ZodError<unknown>

True if the value is a ZodError

Example

if (isZodError(error)) {
  console.error(formatZodError(error));
}

logToolError()

function logToolError(
   logger, 
   toolName, 
   error, 
   durationMs
): void;

Defined in: packages/nexus-agents/src/mcp/middleware/logging.ts:118

Logs a failed tool execution.

Parameters

logger

ILogger

The logger to use

toolName

string

Name of the tool

error

Error

The error that occurred

durationMs

number

Duration of the execution in milliseconds

Returns

void


logToolStart()

function logToolStart(
   logger, 
   toolName, 
   args?
): void;

Defined in: packages/nexus-agents/src/mcp/middleware/logging.ts:76

Logs the start of a tool execution.

Parameters

logger

ILogger

The logger to use

toolName

string

Name of the tool

args?

Record<string, unknown>

Tool arguments (sanitized for logging)

Returns

void


logToolSuccess()

function logToolSuccess(
   logger, 
   toolName, 
   durationMs, 
   resultInfo?
): void;

Defined in: packages/nexus-agents/src/mcp/middleware/logging.ts:96

Logs the successful completion of a tool execution.

Parameters

logger

ILogger

The logger to use

toolName

string

Name of the tool

durationMs

number

Duration of the execution in milliseconds

resultInfo?

Record<string, unknown>

Optional information about the result

Returns

void


mapVoteDecisionToPrDecision()

function mapVoteDecisionToPrDecision(voteDecision): PrReviewDecision;

Defined in: packages/nexus-agents/src/mcp/tools/pr-review-tool.ts:323

Maps a voter’s approve/reject/abstain to PR review semantics.

Parameters

voteDecision

"approve" | "reject" | "abstain"

Returns

PrReviewDecision


normalizeRepoId()

function normalizeRepoId(input): string;

Defined in: packages/nexus-agents/src/mcp/tools/repo-analyze.ts:44

Normalize “owner/repo” from either “owner/repo” or full GitHub URL.

Parameters

input

string

Returns

string


registerExpertsResource()

function registerExpertsResource(server, logger): void;

Defined in: packages/nexus-agents/src/mcp/resources/experts-resource.ts:65

Registers the nexus://experts resource with the MCP server.

Exposes the list of available expert roles (10 built-in experts) with their names, descriptions, and capabilities as a read-only JSON resource.

Parameters

server

McpServer

MCP server instance

logger

ILogger

Logger for registration events

Returns

void


registerModelsResource()

function registerModelsResource(server, logger): void;

Defined in: packages/nexus-agents/src/mcp/resources/models-resource.ts:64

Registers the nexus://models resource with the MCP server.

Exposes the full model capabilities matrix (13 models) as a read-only JSON resource. Data is sourced from the canonical model registry (via getInTreeCapabilitiesMatrix() — backed by the ModelRegistry’s in-tree entries, #2546 slice C3).

Parameters

server

McpServer

MCP server instance

logger

ILogger

Logger for registration events

Returns

void


registerPrompts()

function registerPrompts(server, logger): PromptRegistrationResult;

Defined in: packages/nexus-agents/src/mcp/prompts/index.ts:42

Registers all prompt templates on the MCP server.

Iterates PROMPT_DEFINITIONS and calls server.registerPrompt() for each. The SDK handles argument validation via the Zod schemas defined in each prompt.

Parameters

server

McpServer

The MCP server instance

logger

ILogger

Logger for registration events

Returns

PromptRegistrationResult

The list of registered prompt names


registerResearchResource()

function registerResearchResource(server, logger): void;

Defined in: packages/nexus-agents/src/mcp/resources/research-resource.ts:79

Registers the nexus://research/papers resource with the MCP server.

Exposes the research registry (papers, techniques, stats) as a read-only JSON resource. Gracefully returns an empty result when the registry YAML files are not present.

Parameters

server

McpServer

MCP server instance

logger

ILogger

Logger for registration events

Returns

void


registerResources()

function registerResources(server, logger?): void;

Defined in: packages/nexus-agents/src/mcp/resources/index.ts:38

Registers all MCP resources with the server.

Currently registers 4 resources:

  • nexus://models - AI model capabilities matrix (static)
  • nexus://available-models - live discovered model set per transport (#3406)
  • nexus://research/papers - Research paper registry
  • nexus://experts - Available expert agent roles

Parameters

server

McpServer

MCP server instance

logger?

ILogger

Optional logger (creates default if not provided)

Returns

void


registerTools()

function registerTools(_server, options?): ToolRegistrationResult;

Defined in: packages/nexus-agents/src/mcp/tools/index.ts:623

MCP exports - MCP server implementation Split from index.ts for file size compliance (Issue #285) Updated Issue #538: Added missing tool registration exports

Parameters

_server

McpServer

options?

ToolRegistrationOptions

Returns

ToolRegistrationResult


resolveScannerData()

function resolveScannerData(): Promise<ScannerData>;

Defined in: packages/nexus-agents/src/mcp/tools/repo-security-plan.ts:127

Resolve scanner data: fetch from registry, fall back to embedded.

Returns

Promise<ScannerData>


selectModel()

function selectModel(
   input, 
   requirements, 
   billingMode?
): SelectionResult;

Defined in: packages/nexus-agents/src/mcp/tools/delegate-to-model-helpers.ts:350

Selects the optimal model for a task.

Parameters

input
billing_mode?

"api" | "plan" = ...

model_hint?

string = ...

preferred_capability?

"code" | "reasoning" | "speed" | "context" = ...

task

string = ...

requirements

TaskRequirements

billingMode?

BillingMode = 'api'

Returns

SelectionResult


startStdioServer()

function startStdioServer(config?): Promise<Result<ServerInstance, ServerError>>;

Defined in: packages/nexus-agents/src/mcp/server.ts:217

Starts the MCP server with stdio transport.

This is the main entry point for running the server as a standalone process. The server will communicate over stdin/stdout using the MCP protocol.

Parameters

config?

ServerConfig

Optional server configuration

Returns

Promise<Result<ServerInstance, ServerError>>

Result indicating success or failure

Example

const result = await startStdioServer();
if (!result.ok) {
  console.error('Failed to start server:', result.error.message);
  process.exit(1);
}

toolError()

function toolError(message): ToolResult;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:167

Creates an error tool result.

Back-compat alias for toolStructuredError — maps to the conservative internal / non-retryable envelope. New code should call toolStructuredError directly with the correct category; this alias exists so the ~64 legacy call sites keep working during the #2649 migration sweep.

Parameters

message

string

The error message

Returns

ToolResult

A ToolResult with isError set to true and an internal envelope


toolSuccess()

function toolSuccess(text): ToolResult;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:86

Creates a successful tool result.

Parameters

text

string

The result text

Returns

ToolResult

A ToolResult with the text content

Example

return toolSuccess(JSON.stringify({ status: 'ok', data: result }));

toolSuccessStructured()

function toolSuccessStructured(data): ToolResult;

Defined in: packages/nexus-agents/src/mcp/tools/tool-result.ts:106

Creates a successful tool result with structured content for outputSchema validation.

When a tool is registered with outputSchema, the SDK validates structuredContent against the schema. This helper returns both text (for display) and structured data.

Parameters

data

Record<string, unknown>

The structured result data (must match the tool’s outputSchema)

Returns

ToolResult

A ToolResult with both text content and structuredContent

Example

return toolSuccessStructured({ experts: [...], count: 10 });

validateToolInput()

function validateToolInput<T>(schema, args): Result<T, ValidationError>;

Defined in: packages/nexus-agents/src/mcp/middleware/validation.ts:45

Validates tool input against a Zod schema.

This function should be called at the start of every tool handler to validate incoming arguments before processing.

Type Parameters

T

T

The expected type after validation

Parameters

schema

ZodType<T>

The Zod schema to validate against

args

unknown

The unknown input to validate

Returns

Result<T, ValidationError>

Result containing validated data or a ValidationError

Example

const InputSchema = z.object({
  task: z.string().min(1),
  context: z.record(z.string(), z.unknown()).optional(),
});

server.tool('my_tool', InputSchema.shape, async (args) => {
  const result = validateToolInput(InputSchema, args);
  if (!result.ok) {
    return toolStructuredError({ errorCategory: 'validation', message: result.error.message });
  }
  const { task, context } = result.value;
  // Process validated input...
});

withLogging()

function withLogging<TArgs, TResult>(
   toolName, 
   handler, 
   logger
): (args) => Promise<TResult>;

Defined in: packages/nexus-agents/src/mcp/middleware/logging.ts:170

Higher-order function that wraps a tool handler with logging.

Type Parameters

TArgs

TArgs

Tool argument type

TResult

TResult

Tool result type

Parameters

toolName

string

Name of the tool

handler

(args) => Promise<TResult>

The tool handler function

logger

ILogger

The logger to use

Returns

A wrapped handler with automatic logging

(args) => Promise<TResult>

Example

const wrappedHandler = withLogging(
  'my_tool',
  async (args) => { ... },
  logger
);