Hooks、MCP 与插件策略
只加载托管 Hooks,按身份允许 MCP,并限定插件市场来源。
扩展治理应分别处理执行回调、MCP 身份、插件功能与市场来源。安装默认值不能代替 requirements 约束,插件卸载也不能代表独立连接已撤销。
只允许托管 Hooks
allow_managed_hooks_only = true
[features]
hooks = true
[hooks]
managed_dir = "/enterprise/hooks"
windows_managed_dir = 'C:\enterprise\hooks'管理员还需配置事件和 handler,见Hooks 参考。features.hooks=true 避免用户关闭 Hooks;allow_managed_hooks_only 跳过用户、项目、会话和插件 Hooks,保留受管来源。
requirements 不分发脚本。脚本须由 MDM 或端点管理部署,命令使用受管目录中的绝对路径。Work Cloud 带 local access 的云编排另有范围:支持的企业 Hooks 使用 Global requirements 的远程 mcp_tool,不支持本地命令或插件 Hooks。回调错误、超时和畸形响应可能不阻断工具,必须测试明确拒绝与失败情况,不能将 Hooks 当完整审计记录。
按身份批准 MCP
[mcp_servers.docs]
identity = { command = "codex-mcp" }
[mcp_servers.remote]
identity = { url = "https://example.com/mcp" }示例需替换为实际服务。服务器名称和身份必须同时匹配;存在但为空的 mcp_servers 表会关闭所有 MCP 服务器。字符串 command 只匹配可执行命令,不检查 args、cwd、env 或 env_vars。
需要约束完整调用时使用结构化 command:executable 加逐位置 args 规则。可执行文件、参数数量和顺序必须匹配;参数和 URL 支持 exact、prefix、整值 regex。结构化写法仍不检查 cwd/env/env_vars。插件携带的服务器在 plugins.
控制插件和市场
features.plugins = false 可在支持的本地客户端关闭插件,API-key 登录也适用。要保留插件但限定市场,配置:
[marketplaces]
restrict_to_allowed_sources = true
[marketplaces.allowed_sources.company_plugins]
source = "git"
url = "https://github.com/example/company-plugins.git"
ref = "main"Git 来源匹配规范化仓库 URL,若有 ref 则精确匹配;host_pattern 匹配小写 Git 主机,应使用首尾锚点;local 来源要求绝对规范化路径。未匹配的 add、install、Git refresh 会被拒绝,运行时也会过滤相关市场和插件。
OpenAI curated Git 市场同样需要允许 https://github.com/openai/plugins.git,且不要加 ref 限制。Bundled 和远程安装的 workspace 插件另有机制。这些来源规则适用于支持市场操作的桌面应用和 CLI,不控制网页、手机插件,也不会给 IDE 扩展增加插件支持。