Skip to content

fix(server): disable executable tools in Claude metadata generation - #247

Merged
leoisadev1 merged 3 commits into
mainfrom
fix/claude-metadata-generation
Sep 14, 2026
Merged

leoisadev1 merged 3 commits into
mainfrom
fix/claude-metadata-generation

Conversation

@leoisadev1

@leoisadev1 leoisadev1 commented Sep 10, 2026 •

Copy link
Copy Markdown
Member

Problem

Claude background title and branch generation received the user's first prompt while running with permission bypass. A skill name in that prompt could therefore execute in the background. Verbose Claude CLI output also failed to parse, and JSON-wrapped titles were saved with their wrapper.

Fix

Metadata generation now passes an explicit empty tool set, disables slash commands, hooks, and inherited MCP, and uses dontAsk. Thread titles run in a temporary directory. Shared title cleanup unwraps a JSON object containing a string title. Claude text generation accepts a normal result envelope or a verbose message array and reads structured output from the last result.

Actual Claude chats keep their tools. Subscription environment, MCP headers, and API-key connections are unchanged.

Adapted for Akeru from pingdotgg#4169, pingdotgg#10446, and the dontAsk portion of pingdotgg#10526.

Verification

  • vp test run apps/server/src/textGeneration/ClaudeTextGeneration.test.ts apps/server/src/textGeneration/TextGenerationPrompts.test.ts: 41 passed.
  • Server typecheck passed.
  • Scoped lint, formatting, and git diff --check passed.

The fake CLI asserts the empty tool set, no permission bypass, disabled slash commands, strict MCP config, disabled hooks, dontAsk, and title-directory isolation.

Implemented and verified by GPT-5.6 Sol in T3 Code via the Codex harness.

Claude title and branch generation used permission bypass, so a skill
name in the first prompt could run tools in the background. Verbose CLI
output also failed to parse, and JSON-wrapped titles were saved as-is.

Metadata runs now pass an empty tool set, disable slash commands, hooks,
and inherited MCP, and use dontAsk. Titles run in a temp directory.
Shared title cleanup unwraps a JSON title object, and Claude accepts
verbose result arrays.

Upstream: pingdotgg#4169 pingdotgg#10446 pingdotgg#10526

Grok 4.6 High in Grok Build via Orca.
@vercel

vercel Bot commented Sep 10, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
akeru-bot-landing Building Building Preview Sep 10, 2026 6:25pm UTC

Request Review

@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:M labels Sep 10, 2026
@greptile-apps

greptile-apps Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Greptile Summary

Summary

  • Restricts Claude-backed metadata generation by disabling permission bypasses, executable tools, slash commands, hooks, and inherited MCP configuration.
  • Isolates thread-title generation from the project checkout with a scoped temporary directory.
  • Supports standard result envelopes and verbose message arrays, including JSON-formatted titles, with focused coverage for the new behavior.

Confidence Score: 5/5

Safe to merge.

No outstanding findings.

Reviews (3): Last reviewed commit: "Merge remote-tracking branch 'origin/mai..." | Re-trigger Greptile

@leoisadev1

Copy link
Copy Markdown
Member Author

This is Leo's agent. Independent merge review found a reproducible executable-path regression on a97a52a.

runClaudeCommand changes title-generation cwd to a fresh temporary directory but passes claudeSettings.binaryPath through unchanged. On Linux, resolveSpawnCommand preserves explicit relative paths. A configured ./bin/claude that exists under the request cwd therefore fails to spawn with ENOENT for titles.

I added a throwaway focused test that creates an executable fixture under <request cwd>/bin/claude and calls the shipped generateThreadTitle entry point. It fails with TextGenerationError: Failed to spawn Claude CLI process in 14ms. The identical test passes when only the child's cwd is reverted to the request cwd in a control run. The production source was restored afterward. The existing 41 tests pass but do not cover this case.

Please resolve explicit relative executable paths against the original cwd before moving title generation into its isolated directory. Preserve ordinary PATH lookup, absolute paths, and the new capability restrictions. Add committed coverage and rerun the review-and-fix loop. The scoped request has been delivered to the existing worker; delivery is not a completed repair. Holding merge pending the fix.

@leoisadev1

Copy link
Copy Markdown
Member Author

This is Leo's agent. The relative-executable regression remains on exact head b8aadec despite the current 5/5 assessment. I read the full effective diff and reran the preserved regression through the shipped generateThreadTitle service using an executable fixture at /bin/claude and binaryPath ./bin/claude. It still fails with NotFound / spawn ./bin/claude because the title subprocess runs in the isolated temporary cwd. The production ClaudeTextGeneration.ts is byte-identical to the previously reproduced a97a52a version.

Resolve explicit relative executable paths against the original request cwd before changing the subprocess cwd. Keep bare PATH names and absolute paths working; retain title-directory isolation and all capability restrictions. Commit the real executable-fixture regression and rerun review. This finding remains a repair hold, not an acceptance based on the review score. Orca is unavailable here, so this GitHub follow-up is not a claim of worker delivery or execution.

@leoisadev1
leoisadev1 merged commit 9aa75f5 into main Sep 14, 2026
11 checks passed
@leoisadev1
leoisadev1 deleted the fix/claude-metadata-generation branch September 14, 2026 03:03
This was referenced Sep 14, 2026

This branch was successfully deployed

1 active deployment
Preview — 421f6dbc Deployed Sep 14, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant