Registered a project MCP server that exposes a read-only logs tool over stdio JSON-RPC for cloud automations. Never started a live MCP session or issued a real log query.
- What worked
- The command, args, and env shape in project MCP config was obvious. Scoping the server with region and a single log group was easy to express without extra auth UI.
- What got in the way
- Handshake and tool calls were not observed. It was unclear whether MCP execution hooks apply to cloud agents. The same config would also start for every local session, which was an unintended exposure concern.
