-
Notifications
You must be signed in to change notification settings - Fork 0
feat: add OpenBao-backed MCP guard plugin #1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
papastanb
wants to merge
6
commits into
main
Choose a base branch
from
feat/openbao-mcp-guard
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
6 commits
Select commit
Hold shift + click to select a range
3e92f00
feat: add OpenBao-backed MCP guard plugin
papastanb a4b6398
fix: remove local instruction file dependency
papastanb c70c967
docs: complete public package documentation
papastanb 0742274
fix: address all PR review findings
papastanb 62c692d
fix: add recursive secret scanning for nested arg values
papastanb 89e759e
chore: bump version to 0.3.0 with all PR review fixes
papastanb File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,2 @@ | ||
| dist/ | ||
| node_modules/ |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,22 @@ | ||
| # AGENTS.md | ||
|
|
||
| ## Build & Validation | ||
|
|
||
| - Install: `bun install` | ||
| - Typecheck: `bun run check` | ||
| - Lint: `bun run lint` | ||
| - Build: `bun run build` | ||
|
|
||
| ## Project Intent | ||
|
|
||
| This package is an OpenCode plugin that enforces a secure MCP installation workflow: | ||
|
|
||
| 1. never hardcode MCP secrets in `opencode.json` | ||
| 2. store MCP credentials in OpenBao first | ||
| 3. wire MCP processes through `openbao-mcp-exec` or an equivalent absolute path | ||
|
|
||
| ## Conventions | ||
|
|
||
| - Keep public docs path-agnostic: do not reference personal home directories in README examples | ||
| - Treat the TUI module as a first-class surface for OpenCode plugin UX | ||
| - Prefer minimal, deterministic plugin hooks over complex magic |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,25 @@ | ||
| # Changelog | ||
|
|
||
| ## 0.3.0 | ||
|
|
||
| - fix HARDCODED_SECRET_RE bypass by scanning raw string values instead of JSON.stringify'd args | ||
| - fix Bun.file().exists() for directory checks by using node:fs/promises stat | ||
| - move OPENBAO_EXECUTABLE constant to top of file near other constants | ||
| - fix TUI command trigger by removing leading slash from 'add-secure-mcp' | ||
| - add recursive hasSecretInValue() to detect secrets in nested objects and arrays | ||
| - rewrite all commits with correct author identity (papastanb) | ||
|
|
||
| ## 0.2.0 | ||
|
|
||
| - replace hardcoded personal `openbao-mcp-exec` paths with path-agnostic guidance | ||
| - add fuller public package metadata for npm and GitHub | ||
| - add dedicated documentation for setup, releases, and LLM-facing usage | ||
| - keep TUI integration and `/add-secure-mcp` as the primary onboarding surface | ||
|
|
||
| ## 0.1.1 | ||
|
|
||
| - remove dependency on a separate local instructions file in `opencode.json` | ||
|
|
||
| ## 0.1.0 | ||
|
|
||
| - initial public release of the OpenBao-backed MCP guard plugin for OpenCode |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,21 @@ | ||
| MIT License | ||
|
|
||
| Copyright (c) 2026 Stan | ||
|
|
||
| Permission is hereby granted, free of charge, to any person obtaining a copy | ||
| of this software and associated documentation files (the "Software"), to deal | ||
| in the Software without restriction, including without limitation the rights | ||
| to use, copy, modify, merge, publish, distribute, sublicense, and/or sell | ||
| copies of the Software, and to permit persons to whom the Software is | ||
| furnished to do so, subject to the following conditions: | ||
|
|
||
| The above copyright notice and this permission notice shall be included in all | ||
| copies or substantial portions of the Software. | ||
|
|
||
| THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR | ||
| IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, | ||
| FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE | ||
| AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER | ||
| LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, | ||
| OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE | ||
| SOFTWARE. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,145 @@ | ||
| # opencode-openbao-mcp-guard | ||
|
|
||
| OpenCode plugin that standardizes secure MCP installation when an MCP needs an API key or token. | ||
|
|
||
| This package is self-contained from the OpenCode side: it does not require a separate local instruction file in `opencode.json`. Guidance is embedded in the plugin behavior, the TUI surface, and the `/add-secure-mcp` command. | ||
|
|
||
| ## Version | ||
|
|
||
| - Current package version: `0.2.0` | ||
| - npm: `https://www.npmjs.com/package/opencode-openbao-mcp-guard` | ||
| - GitHub: `https://github.com/papastanb/Bao_MCP` | ||
|
|
||
| ## What it does | ||
|
|
||
| - blocks obvious hardcoded secrets in `opencode.json` and `opencode.jsonc` | ||
| - injects a secure MCP reminder into relevant chats | ||
| - registers a guided `/add-secure-mcp` command | ||
| - exposes a TUI module for OpenCode plugin integration | ||
| - keeps the OpenBao-first workflow embedded in the plugin behavior | ||
|
|
||
| ## Security model | ||
|
|
||
| For MCPs that need an API key: | ||
|
|
||
| 1. store the key in OpenBao first | ||
| 2. configure the MCP to fetch the key at runtime through `openbao-mcp-exec` | ||
| 3. never write the key directly into `opencode.json` | ||
|
|
||
| OpenBao storage example: | ||
|
|
||
| ```bash | ||
| bao kv put -address=http://127.0.0.1:8200 -tls-skip-verify -mount=secret context7/api_key key=TA_CLE_API | ||
| ``` | ||
|
|
||
| OpenCode MCP example: | ||
|
|
||
| ```json | ||
| "context7": { | ||
| "type": "local", | ||
| "command": [ | ||
| "openbao-mcp-exec", | ||
| "secret", | ||
| "context7/api_key", | ||
| "key", | ||
| "--", | ||
| "npx", | ||
| "-y", | ||
| "@upstash/context7-mcp", | ||
| "--api-key" | ||
| ] | ||
| } | ||
| ``` | ||
|
coderabbitai[bot] marked this conversation as resolved.
|
||
|
|
||
| If `openbao-mcp-exec` is not on `PATH`, replace it with an absolute path in your local config. | ||
|
|
||
| ## Install in OpenCode | ||
|
|
||
| Add the plugin to your global OpenCode config: | ||
|
|
||
| ```json | ||
| { | ||
| "plugin": [ | ||
| "opencode-openbao-mcp-guard" | ||
| ] | ||
| } | ||
| ``` | ||
|
|
||
| OpenCode will install the package automatically. | ||
|
|
||
| ## TUI integration | ||
|
|
||
| This package ships both: | ||
|
|
||
| - a server plugin entrypoint | ||
| - a TUI plugin entrypoint (`./tui`) | ||
|
|
||
| The TUI module registers a visible command launcher and shows a first-load toast so the plugin is discoverable in the TUI plugin list and command picker. | ||
|
|
||
| ## Slash command | ||
|
|
||
| - `/add-secure-mcp`: guided secure MCP installation flow | ||
|
|
||
| The command tells the model to: | ||
|
|
||
| - avoid hardcoded secrets | ||
| - ask for the MCP package/launcher details | ||
| - remind the user to store the key in OpenBao first | ||
| - generate the correct `command` array using `openbao-mcp-exec` | ||
|
|
||
| ## OpenBao setup | ||
|
|
||
| Minimal pattern: | ||
|
|
||
| ```bash | ||
| bao kv put -address=http://127.0.0.1:8200 -tls-skip-verify -mount=secret <mcp>/api_key key=TA_CLE_API | ||
| ``` | ||
|
|
||
| More details: | ||
|
|
||
| - [`docs/OPENBAO_SETUP.md`](./docs/OPENBAO_SETUP.md) | ||
|
|
||
| ## Setup for LLMs | ||
|
|
||
| If an LLM or coding agent is using this plugin, it should follow these rules: | ||
|
|
||
| 1. never hardcode API keys in `opencode.json` | ||
| 2. always ask the user to store the secret in OpenBao first | ||
| 3. prefer `openbao-mcp-exec` on `PATH` | ||
| 4. if the helper is not on `PATH`, request or use an explicit absolute path locally | ||
|
|
||
| Dedicated guide: | ||
|
|
||
| - [`docs/LLM_SETUP.md`](./docs/LLM_SETUP.md) | ||
|
|
||
| ## Development | ||
|
|
||
| ```bash | ||
| bun install | ||
| bun run check | ||
| bun run lint | ||
| bun run build | ||
| ``` | ||
|
|
||
| ## Local development install | ||
|
|
||
| ```json | ||
| { | ||
| "plugin": [ | ||
| "file:///absolute/path/to/Bao_MCP" | ||
| ] | ||
| } | ||
| ``` | ||
|
|
||
| During development, loading the package root is preferred over pointing to a single built file because it keeps the server and TUI plugin surfaces together. | ||
|
|
||
| ## Release process | ||
|
|
||
| See: | ||
|
|
||
| - [`CHANGELOG.md`](./CHANGELOG.md) | ||
| - [`RELEASE.md`](./RELEASE.md) | ||
|
|
||
| ## License | ||
|
|
||
| MIT | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,36 @@ | ||
| # Release Guide | ||
|
|
||
| ## Validate | ||
|
|
||
| ```bash | ||
| bun install | ||
| bun run check | ||
| bun run lint | ||
| bun run build | ||
| ``` | ||
|
|
||
| ## Publish npm | ||
|
|
||
| ```bash | ||
| npm publish --access public | ||
| ``` | ||
|
|
||
| ## Create Git tag | ||
|
|
||
| ```bash | ||
| git tag vX.Y.Z | ||
| git push origin vX.Y.Z | ||
| ``` | ||
|
|
||
| ## Create GitHub release | ||
|
|
||
| ```bash | ||
| gh release create vX.Y.Z --generate-notes | ||
| ``` | ||
|
|
||
| ## Post-release checks | ||
|
|
||
| ```bash | ||
| npm view opencode-openbao-mcp-guard version | ||
| gh release view vX.Y.Z | ||
| ``` |
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🟡 README displays stale version
0.2.0while package.json is at0.3.0The README at line 9 states
Current package version: 0.2.0, butpackage.json:3has"version": "0.3.0"andCHANGELOG.md:3lists0.3.0as the latest release. This was likely missed when bumping the version in commit89e759e. Users and integrations that check the README for the current version will see outdated information.Was this helpful? React with 👍 or 👎 to provide feedback.