Boss Agent Integration Audit Report
Scope Reviewed
- Boss Agent orchestration API surfaces (
miz-oki-adk-agents/boss/boss_agent_core.py). - VS Code extension integration (
vscode-boss-agent-extension). - Chrome extension integration (
chrome-boss-agent-extension). - Front-end login wiring (
miz-oki-command-center-ui).
Architecture Summary
Boss Agent Core API
The primary Boss Agent service exposes:
GET /healthPOST /api/v1/chatPOST /api/v1/chat/streamGET /api/v1/mcp/toolsPOST /api/v1/mcp/tools/{tool_name}/invokeGET /api/v1/cells/health/all
These routes are implemented in boss_agent_core.py and represent the contract used by client integrations.
VS Code Extension
The extension is designed around a dedicated API client (src/client.ts) and panel/providers for:
- Chat & stream handling
- MCP tool discovery/invoke
- Cell status monitoring
Chrome Extension
The extension background script contains the runtime API client and message router for:
- Popup + side panel chat
- Quick tool invocations
- Options page connectivity test
Front-end Login
The login page uses useTenantAuth context hooks and expects to be wrapped by TenantAuthProvider in the global provider tree.
Findings (Before Fixes)
-
Front-end login provider missing -
useTenantAuth()was used on/login, butTenantAuthProviderwas not included in app-level providers. - Impact: Runtime crash (useTenantAuth must be used within a TenantAuthProvider). -
Chrome extension tool invoke endpoint mismatch - Client called legacy
POST /api/v1/mcp/invoke. - Core service exposesPOST /api/v1/mcp/tools/{tool_name}/invoke. - Impact: tool invocation failures against current API. -
Chrome extension cell health endpoint mismatch - Client called
/api/v1/cells/statuswhile core contract uses/api/v1/cells/health/all. - Impact: status panel data failure/inconsistency. -
Chrome extension streaming payload/event mismatch - Sent
modeinstead oforchestration_modeand lackedstreamflags. - Parsing expectedtoken; server emits typed SSE events (type: token,content,done). - Impact: broken or partial streaming UX. -
Chrome options save message not applied by background worker - Options sent
SETTINGS_UPDATED, but background script ignored it. - Impact: updated API URL not guaranteed to apply until extension reload. -
VS Code extension tool invoke endpoint mismatch - Used legacy
/api/v1/mcp/invokeonly. - Impact: tool invoke may fail against new deployments. -
VS Code extension non-stream chat response shape variability - Some backends may return
response+conversation_idinstead ofmessage+conversationId. - Impact: empty responses in UI depending on deployment variant.
Fixes Implemented
- Added
TenantAuthProviderto global provider composition so login and auth hooks are valid. - Updated Chrome extension to use canonical tool invoke path
/api/v1/mcp/tools/{tool}/invoke. - Updated Chrome extension to use
/api/v1/cells/health/all. - Updated Chrome chat/stream payloads and SSE parsing to the current Boss Agent schema.
- Added background handling for
SETTINGS_UPDATEDso API URL and runtime config update immediately. - Updated VS Code extension tool invoke to use canonical endpoint, with fallback to legacy endpoint when 404.
- Updated VS Code non-stream chat parsing to normalize both old/new response field names.
Validation Run
- VS Code extension TypeScript compile succeeds.
- Chrome extension JS syntax checks succeed.
- Command Center lint could not run in this environment because
nextbinary is unavailable (dependencies not installed). - External Cloud Run health checks were attempted but blocked by environment proxy (
403 Forbiddentunnel), so runtime connectivity could not be independently verified from this environment.
Remaining Recommended Work
- Add automated contract tests for extension clients against a mocked Boss Agent API schema.
- Add CI checks for Chrome extension (lint + unit test harness).
- Add VS Code extension integration tests around stream and tool invoke fallback paths.
- Add an environment bootstrap script for
miz-oki-command-center-uito ensurenext lintis runnable in CI/dev containers. - Standardize on one canonical chat response schema across all Boss Agent deployments to reduce client normalization logic.