Conversation
Add Alibaba Cloud Coding Plan configuration with OpenAI and Anthropic protocol compatible endpoints
boofpackdev
added a commit
to boofpackdev/openclaude
that referenced
this pull request
Apr 4, 2026
…election priority - Add ProviderRegistry singleton class with detect() method - Implement provider selection priority: 1. HERMES_ENDPOINT env var -> hermes provider 2. CLAUDE_CODE_USE_OPENAI=1 -> openai provider 3. Config file provider preference 4. Default: hermes provider - Add register(), get(), detect(), list() methods - Add unit tests for registry selection logic - Add ProviderInfo interface for registry listing Closes Twigpine#6
Flo5k5
added a commit
to Flo5k5/openclaude
that referenced
this pull request
Apr 12, 2026
- Fix permission rule field: expression → ruleContent (Copilot #1) - Handle empty command prefix: skip rule creation (Copilot Twigpine#2) - Remove unused useTheme() import (Copilot Twigpine#3) - Save permission rules under 'Bash' toolName so bashToolHasPermission can match them — Monitor delegates to Bash permission system (Copilot Twigpine#4) - Remove unused logError import from MonitorMcpTask (Copilot Twigpine#6) - Copilot Twigpine#5 (getAppState throws): same pattern as BashTool:915, not a bug
kevincodex1
pushed a commit
that referenced
this pull request
Apr 13, 2026
* feat: implement Monitor tool for streaming shell output Add the Monitor tool that executes shell commands in the background and streams stdout line-by-line as notifications to the model. This enables real-time monitoring of logs, builds, and long-running processes. Implementation: - MonitorTool (src/tools/MonitorTool/) — spawns LocalShellTask with kind='monitor', returns immediately with task ID - MonitorMcpTask (src/tasks/MonitorMcpTask/) — task lifecycle management and agent cleanup via killMonitorMcpTasksForAgent() - MonitorPermissionRequest — permission dialog component The codebase already had all integration points wired (tools.ts, tasks.ts, PermissionRequest.tsx, LocalShellTask kind='monitor', BashTool prompt). This PR provides the missing implementations. * fix: command-specific permission rule + architecture docs - MonitorPermissionRequest: "don't ask again" now creates a command-prefix rule (like BashTool) instead of a blanket tool-name-only rule that would auto-allow all Monitor commands - MonitorMcpTask: clarify architecture comments explaining why monitor_mcp type exists as a registry stub while actual tasks are local_bash with kind='monitor' * fix: address Copilot review feedback - Fix permission rule field: expression → ruleContent (Copilot #1) - Handle empty command prefix: skip rule creation (Copilot #2) - Remove unused useTheme() import (Copilot #3) - Save permission rules under 'Bash' toolName so bashToolHasPermission can match them — Monitor delegates to Bash permission system (Copilot #4) - Remove unused logError import from MonitorMcpTask (Copilot #6) - Copilot #5 (getAppState throws): same pattern as BashTool:915, not a bug
4 tasks
kevincodex1
added a commit
to kevincodex1/openclaude
that referenced
this pull request
Apr 21, 2026
Addresses the security review on feat/bash-command-safety-classifier. Each finding traced by reviewer is fixed locally; adversarial tests cover each bypass pattern. P0 — parser bypasses (CRITICAL / HIGH): #1 Escaped backslash before close quote — `echo "test\\" && rm -rf /` slipped through as one quoted echo. The prior `input[i-1] !== '\\'` check fails when the backslash itself is escaped. Replaced with an isCharEscaped() helper that counts consecutive backslashes; a quote is escaped only when preceded by an odd count. Applied in BOTH splitCompound AND tokenize so they agree on quote boundaries. #2 Process substitution not detected — `cat <(curl ...)` passed the cat safe gate. tokenize now returns null on `<(` / `>(` same as it did for `$(` / backticks, degrading to 'unknown'. Twigpine#3 Newline as command separator — `echo safe\nrm -rf /` was treated as one line by splitCompound (bash splits on \n = ;). Added \n to the separator list alongside ; | &. P1 — classification bypasses (MEDIUM): Twigpine#4 Sensitive-path denylist — cat/head/tail/less/more/file/stat/wc and readlink/realpath now consult SENSITIVE_PATH_PATTERNS. /etc/shadow, ~/.ssh/id_rsa, /proc/*/environ, /dev/sd*, ~/.aws/credentials, ~/.kube/config, id_rsa / *.pem / *.key etc. degrade to 'unknown'. Public keys (*.pub) and normal files remain safe. Twigpine#5 `git config key value` misclassified — removed `config` from the READ_ONLY_SUBCOMMANDS list and added explicit unsafe gate: two+ positional args with no --get/--list is a set, marked unsafe. --unset / --replace-all / --add / --unset-all also marked unsafe. Single-arg read form falls to 'unknown' (defers to existing rules). Twigpine#6 `git stash` (bare) misclassified — equivalent to `git stash push`, mutates worktree + index. Safe path now requires `git stash list` or `git stash show`; everything else in stash falls to unsafe or unknown. P2 — hygiene (LOW): Twigpine#7 env / printenv removed from ALWAYS_SAFE_COMMANDS. Plain `env` dumps all environment variables (API keys, tokens) to the caller — not safe to auto-approve. FOO=bar cmd idiom still works via the existing env-assignment-prefix stripping. Twigpine#8 git gc / prune / repack / bisect removed from READ_ONLY_SUBCOMMANDS and added to the unsafe gate. gc repacks + deletes loose objects; bisect start/good/bad/reset/run/skip/terms/replay mutate HEAD. Tests: 35 new adversarial cases across all 8 findings, plus regression coverage (public keys still safe, FOO=bar pwd still safe, git stash list/show still safe). Full suite: 1187/1187 pass. PR intent scan: clean. Co-Authored-By: OpenClaude <openclaude@gitlawb.com>
C1ph3r404
referenced
this pull request
in C1ph3r404/openclaude
Apr 29, 2026
* feat: implement Monitor tool for streaming shell output Add the Monitor tool that executes shell commands in the background and streams stdout line-by-line as notifications to the model. This enables real-time monitoring of logs, builds, and long-running processes. Implementation: - MonitorTool (src/tools/MonitorTool/) — spawns LocalShellTask with kind='monitor', returns immediately with task ID - MonitorMcpTask (src/tasks/MonitorMcpTask/) — task lifecycle management and agent cleanup via killMonitorMcpTasksForAgent() - MonitorPermissionRequest — permission dialog component The codebase already had all integration points wired (tools.ts, tasks.ts, PermissionRequest.tsx, LocalShellTask kind='monitor', BashTool prompt). This PR provides the missing implementations. * fix: command-specific permission rule + architecture docs - MonitorPermissionRequest: "don't ask again" now creates a command-prefix rule (like BashTool) instead of a blanket tool-name-only rule that would auto-allow all Monitor commands - MonitorMcpTask: clarify architecture comments explaining why monitor_mcp type exists as a registry stub while actual tasks are local_bash with kind='monitor' * fix: address Copilot review feedback - Fix permission rule field: expression → ruleContent (Copilot #1) - Handle empty command prefix: skip rule creation (Copilot #2) - Remove unused useTheme() import (Copilot #3) - Save permission rules under 'Bash' toolName so bashToolHasPermission can match them — Monitor delegates to Bash permission system (Copilot #4) - Remove unused logError import from MonitorMcpTask (Copilot #6) - Copilot #5 (getAppState throws): same pattern as BashTool:915, not a bug
kevincodex1
added a commit
to kevincodex1/openclaude
that referenced
this pull request
May 6, 2026
Addresses the security review on feat/bash-command-safety-classifier. Each finding traced by reviewer is fixed locally; adversarial tests cover each bypass pattern. P0 — parser bypasses (CRITICAL / HIGH): #1 Escaped backslash before close quote — `echo "test\\" && rm -rf /` slipped through as one quoted echo. The prior `input[i-1] !== '\\'` check fails when the backslash itself is escaped. Replaced with an isCharEscaped() helper that counts consecutive backslashes; a quote is escaped only when preceded by an odd count. Applied in BOTH splitCompound AND tokenize so they agree on quote boundaries. #2 Process substitution not detected — `cat <(curl ...)` passed the cat safe gate. tokenize now returns null on `<(` / `>(` same as it did for `$(` / backticks, degrading to 'unknown'. Twigpine#3 Newline as command separator — `echo safe\nrm -rf /` was treated as one line by splitCompound (bash splits on \n = ;). Added \n to the separator list alongside ; | &. P1 — classification bypasses (MEDIUM): Twigpine#4 Sensitive-path denylist — cat/head/tail/less/more/file/stat/wc and readlink/realpath now consult SENSITIVE_PATH_PATTERNS. /etc/shadow, ~/.ssh/id_rsa, /proc/*/environ, /dev/sd*, ~/.aws/credentials, ~/.kube/config, id_rsa / *.pem / *.key etc. degrade to 'unknown'. Public keys (*.pub) and normal files remain safe. Twigpine#5 `git config key value` misclassified — removed `config` from the READ_ONLY_SUBCOMMANDS list and added explicit unsafe gate: two+ positional args with no --get/--list is a set, marked unsafe. --unset / --replace-all / --add / --unset-all also marked unsafe. Single-arg read form falls to 'unknown' (defers to existing rules). Twigpine#6 `git stash` (bare) misclassified — equivalent to `git stash push`, mutates worktree + index. Safe path now requires `git stash list` or `git stash show`; everything else in stash falls to unsafe or unknown. P2 — hygiene (LOW): Twigpine#7 env / printenv removed from ALWAYS_SAFE_COMMANDS. Plain `env` dumps all environment variables (API keys, tokens) to the caller — not safe to auto-approve. FOO=bar cmd idiom still works via the existing env-assignment-prefix stripping. Twigpine#8 git gc / prune / repack / bisect removed from READ_ONLY_SUBCOMMANDS and added to the unsafe gate. gc repacks + deletes loose objects; bisect start/good/bad/reset/run/skip/terms/replay mutate HEAD. Tests: 35 new adversarial cases across all 8 findings, plus regression coverage (public keys still safe, FOO=bar pwd still safe, git stash list/show still safe). Full suite: 1187/1187 pass. PR intent scan: clean. Co-Authored-By: OpenClaude <openclaude@gitlawb.com>
The-FOOL-00
pushed a commit
to The-FOOL-00/openclaude
that referenced
this pull request
May 24, 2026
* feat: implement Monitor tool for streaming shell output Add the Monitor tool that executes shell commands in the background and streams stdout line-by-line as notifications to the model. This enables real-time monitoring of logs, builds, and long-running processes. Implementation: - MonitorTool (src/tools/MonitorTool/) — spawns LocalShellTask with kind='monitor', returns immediately with task ID - MonitorMcpTask (src/tasks/MonitorMcpTask/) — task lifecycle management and agent cleanup via killMonitorMcpTasksForAgent() - MonitorPermissionRequest — permission dialog component The codebase already had all integration points wired (tools.ts, tasks.ts, PermissionRequest.tsx, LocalShellTask kind='monitor', BashTool prompt). This PR provides the missing implementations. * fix: command-specific permission rule + architecture docs - MonitorPermissionRequest: "don't ask again" now creates a command-prefix rule (like BashTool) instead of a blanket tool-name-only rule that would auto-allow all Monitor commands - MonitorMcpTask: clarify architecture comments explaining why monitor_mcp type exists as a registry stub while actual tasks are local_bash with kind='monitor' * fix: address Copilot review feedback - Fix permission rule field: expression → ruleContent (Copilot Twigpine#1) - Handle empty command prefix: skip rule creation (Copilot Twigpine#2) - Remove unused useTheme() import (Copilot Twigpine#3) - Save permission rules under 'Bash' toolName so bashToolHasPermission can match them — Monitor delegates to Bash permission system (Copilot Twigpine#4) - Remove unused logError import from MonitorMcpTask (Copilot Twigpine#6) - Copilot Twigpine#5 (getAppState throws): same pattern as BashTool:915, not a bug
discopops
pushed a commit
to discopops/openclaude
that referenced
this pull request
May 28, 2026
* feat: implement Monitor tool for streaming shell output Add the Monitor tool that executes shell commands in the background and streams stdout line-by-line as notifications to the model. This enables real-time monitoring of logs, builds, and long-running processes. Implementation: - MonitorTool (src/tools/MonitorTool/) — spawns LocalShellTask with kind='monitor', returns immediately with task ID - MonitorMcpTask (src/tasks/MonitorMcpTask/) — task lifecycle management and agent cleanup via killMonitorMcpTasksForAgent() - MonitorPermissionRequest — permission dialog component The codebase already had all integration points wired (tools.ts, tasks.ts, PermissionRequest.tsx, LocalShellTask kind='monitor', BashTool prompt). This PR provides the missing implementations. * fix: command-specific permission rule + architecture docs - MonitorPermissionRequest: "don't ask again" now creates a command-prefix rule (like BashTool) instead of a blanket tool-name-only rule that would auto-allow all Monitor commands - MonitorMcpTask: clarify architecture comments explaining why monitor_mcp type exists as a registry stub while actual tasks are local_bash with kind='monitor' * fix: address Copilot review feedback - Fix permission rule field: expression → ruleContent (Copilot Twigpine#1) - Handle empty command prefix: skip rule creation (Copilot Twigpine#2) - Remove unused useTheme() import (Copilot Twigpine#3) - Save permission rules under 'Bash' toolName so bashToolHasPermission can match them — Monitor delegates to Bash permission system (Copilot Twigpine#4) - Remove unused logError import from MonitorMcpTask (Copilot Twigpine#6) - Copilot Twigpine#5 (getAppState throws): same pattern as BashTool:915, not a bug
kevincodex1
added a commit
to kevincodex1/openclaude
that referenced
this pull request
Jun 23, 2026
Addresses the security review on feat/bash-command-safety-classifier. Each finding traced by reviewer is fixed locally; adversarial tests cover each bypass pattern. P0 — parser bypasses (CRITICAL / HIGH): #1 Escaped backslash before close quote — `echo "test\\" && rm -rf /` slipped through as one quoted echo. The prior `input[i-1] !== '\\'` check fails when the backslash itself is escaped. Replaced with an isCharEscaped() helper that counts consecutive backslashes; a quote is escaped only when preceded by an odd count. Applied in BOTH splitCompound AND tokenize so they agree on quote boundaries. #2 Process substitution not detected — `cat <(curl ...)` passed the cat safe gate. tokenize now returns null on `<(` / `>(` same as it did for `$(` / backticks, degrading to 'unknown'. Twigpine#3 Newline as command separator — `echo safe\nrm -rf /` was treated as one line by splitCompound (bash splits on \n = ;). Added \n to the separator list alongside ; | &. P1 — classification bypasses (MEDIUM): Twigpine#4 Sensitive-path denylist — cat/head/tail/less/more/file/stat/wc and readlink/realpath now consult SENSITIVE_PATH_PATTERNS. /etc/shadow, ~/.ssh/id_rsa, /proc/*/environ, /dev/sd*, ~/.aws/credentials, ~/.kube/config, id_rsa / *.pem / *.key etc. degrade to 'unknown'. Public keys (*.pub) and normal files remain safe. Twigpine#5 `git config key value` misclassified — removed `config` from the READ_ONLY_SUBCOMMANDS list and added explicit unsafe gate: two+ positional args with no --get/--list is a set, marked unsafe. --unset / --replace-all / --add / --unset-all also marked unsafe. Single-arg read form falls to 'unknown' (defers to existing rules). Twigpine#6 `git stash` (bare) misclassified — equivalent to `git stash push`, mutates worktree + index. Safe path now requires `git stash list` or `git stash show`; everything else in stash falls to unsafe or unknown. P2 — hygiene (LOW): Twigpine#7 env / printenv removed from ALWAYS_SAFE_COMMANDS. Plain `env` dumps all environment variables (API keys, tokens) to the caller — not safe to auto-approve. FOO=bar cmd idiom still works via the existing env-assignment-prefix stripping. Twigpine#8 git gc / prune / repack / bisect removed from READ_ONLY_SUBCOMMANDS and added to the unsafe gate. gc repacks + deletes loose objects; bisect start/good/bad/reset/run/skip/terms/replay mutate HEAD. Tests: 35 new adversarial cases across all 8 findings, plus regression coverage (public keys still safe, FOO=bar pwd still safe, git stash list/show still safe). Full suite: 1187/1187 pass. PR intent scan: clean. Co-Authored-By: OpenClaude <openclaude@gitlawb.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add Alibaba Cloud Coding Plan configuration with OpenAI and Anthropic protocol compatible endpoints