config: tool groups for tgclient and synapse
Both servers declare no groups, so every profile asking for "tgclient":
["read", "write"] resolved to nothing: resolve_group reads the static
config, returned [], and no mcp__tgclient__* name ever reached the agent.
Worse, the server's own instructions did reach it — they are selected by
server name, not by group — so the model was told about tools it did not
have. synapse is not exposed by any profile, so its groups change nothing
today; without them, exposing it would repeat the same failure.

read  — observe only.
write — changes to sources, types, targets and routing rules.
admin — hub-wide knobs, not routing: issuing and revoking a source's API
        key, and settings overrides on top of .env. The same fence
        gnexus-book puts around its service-operator tools.
1 parent 726ad08 commit 456707a2c961a61bf99e421940b155eb1df8100a
@Eugene Sukhodolskiy Eugene Sukhodolskiy authored 9 hours ago
Showing 2 changed files
View
mcp_servers.d/synapse.json
View
mcp_servers.d/tgclient.json