Sea Haven MCP platform — trust-tiered MCP servers + Cognito/Google auth broker, replacing seahaven-slack-bot and exec-aide (design phase)
Find a file
Adam Moussa c5b7550eaa Harden auth + finance redaction (sh-security-review confirmed mediums)
Two confirmed medium findings from the agentic security review:

- Fail-open SH_MCP_ENV: config defaulted to 'local' when the var was unset,
  so a deploy that forgot SH_MCP_ENV=aws would silently run LocalAuthProvider
  and accept static dev bearer tokens (dev-finance-admin -> finance:admin).
  Now fail-closed: SH_MCP_ENV must be explicitly 'local' or 'aws' or the
  server refuses to start. Plus an independent guard in LocalAuthProvider
  that refuses to construct in an AWS runtime (AWS_LAMBDA_FUNCTION_NAME /
  AWS_EXECUTION_ENV present), regardless of the env flag.

- Finance egress redaction gap: redactDeep only wholesale-masked a sensitive
  key when its value was a scalar; an object/array under a sensitive key was
  recursed into, letting a bare nested value (e.g. {account:{number:...}})
  escape the keyword-gated pattern matcher. Now the entire subtree under a
  sensitive key is masked. No current finance tool emitted such shapes (all
  flat strings), so this closes a latent hole in the universal safety net.

+4 tests (subtree redaction, AWS-runtime guard). 411 pass; coverage gate green.

Review also produced lows (memo free-text digits, unsalted argsHash,
unauth /openapi.json by-design, session-cap no-reset by-design) tracked
separately; 0 confirmed critical/high — review verdict PASS.
2026-06-26 13:23:02 -04:00
.github/workflows Phase 0b slice: monorepo scaffold + @sh-mcp/shared core + integration packages (#2) 2026-06-26 12:42:17 -04:00
.security-review Suppress pre-existing dev-tooling + out-of-scope scanner findings 2026-06-26 12:50:38 -04:00
docs Add Agentforce migration & architecture plan (#1) 2026-06-26 12:47:04 -04:00
packages Harden auth + finance redaction (sh-security-review confirmed mediums) 2026-06-26 13:23:02 -04:00
servers Harden auth + finance redaction (sh-security-review confirmed mediums) 2026-06-26 13:23:02 -04:00
.editorconfig Phase 0b slice: monorepo scaffold + @sh-mcp/shared core + integration packages (#2) 2026-06-26 12:42:17 -04:00
.gitignore Phase 0b slice: monorepo scaffold + @sh-mcp/shared core + integration packages (#2) 2026-06-26 12:42:17 -04:00
.prettierignore Add security-weighted test suite + coverage gate; wire tooling 2026-06-26 12:48:26 -04:00
.prettierrc Phase 0b slice: monorepo scaffold + @sh-mcp/shared core + integration packages (#2) 2026-06-26 12:42:17 -04:00
eslint.config.js Add security-weighted test suite + coverage gate; wire tooling 2026-06-26 12:48:26 -04:00
package-lock.json Address CodeQL findings: bound ajv error work + edge rate limiting 2026-06-26 13:01:12 -04:00
package.json Add security-weighted test suite + coverage gate; wire tooling 2026-06-26 12:48:26 -04:00
README.md Initial commit: sh-mcp design and plan 2026-06-09 19:25:24 -04:00
tsconfig.base.json Phase 0b slice: monorepo scaffold + @sh-mcp/shared core + integration packages (#2) 2026-06-26 12:42:17 -04:00
tsconfig.json Add security-weighted test suite + coverage gate; wire tooling 2026-06-26 12:48:26 -04:00
vitest.config.ts Add security-weighted test suite + coverage gate; wire tooling 2026-06-26 12:48:26 -04:00

sh-mcp

Sea Haven MCP platform. A TypeScript monorepo of trust-tiered MCP servers that expose Sea Haven's proprietary integrations as tools, plus the Cognito/Google auth broker and the rebuilt scheduled jobs. This service replaces seahaven-slack-bot and exec-aide, which are deprecated completely; the conversational surface becomes a configurable Slack task agent.

Status: DESIGN / PLANNING. Not built. No stack deployed. The full design, auth architecture, scope matrix, and build plan live in docs/design.md. Read it before writing any code.

Shape (planned)

  • MCP servers (trust-tiered, remote HTTP, per-server IAM):
    • sh-mcp-ops — read-mostly, agent-facing (WO/PO/site lookups, KB search, Google Maps, Gmail/Calendar, tasks, reminders).
    • sh-mcp-finance — sensitive, read-only, audited (QBO vendor search, payment lookups).
    • sh-mcp-physical — DEFERRED, admin/out-of-band only (Lenel/Yealink/3CX control).
  • Auth — Google Workspace is the single IdP; an Amazon Cognito user pool federated to Google issues scoped, audience-bound JWTs; group → scope mapping via a pre-token Lambda. See design §2.
  • Jobs — rebuilt proactive Lambdas (email classify/digest, KB syncs).
  • Language — TypeScript everywhere (servers, packages, CDK, jobs).

Open decisions

  • Task-agent surface: Agentforce (recommended) vs marketplace Claude app vs custom Bolt assistant (design §12). Drives the model + guardrail story.
  • Endpoint exposure specifics (Slack egress ranges / WAF) — design §9 / §11.

Layout (target)

packages/   shared + one package per integration
servers/    sh-mcp-ops, sh-mcp-finance  (CDK stacks)
auth/       cognito, pre-token-lambda, group-sync-lambda
jobs/       rebuilt scheduled Lambdas
docs/       design.md  (the canonical plan)

See docs/design.md for the authoritative spec.