Skip to content

fix: keep GitHub MCP credentials out of argv - #209

Merged
shunkakinoki merged 1 commit into
mainfrom
fix/github-mcp-argv-safe
Sep 1, 2026
Merged

shunkakinoki merged 1 commit into
mainfrom
fix/github-mcp-argv-safe

Conversation

@shunkakinoki

@shunkakinoki shunkakinoki commented Sep 1, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Replace the shell-based GitHub MCP launcher with Ruler's native HTTP transport.
  • Prevent GitHub OAuth credentials from being expanded into child-process argv.

Before / after

Before After
gh auth token was interpolated into an mcp-remote process argument. The GitHub MCP endpoint is configured directly as an HTTP server.

Breaking and irreversible changes

  • Behavioral: GitHub MCP clients use native HTTP authentication instead of a shell launcher.
  • Compile-time: None.
  • Durable state and rollback: None. Revert this commit to restore the previous configuration.

Deliberate boundaries

  • OAuth credential rotation and contaminated-process termination were performed operationally and are not repository changes.

Verification

  • bun run format
  • bun run lint
  • bun run check
  • git diff --check
  • jq empty .ruler/mcp.json

Summary by cubic

Replaces the shell-based GitHub MCP launcher with Ruler's native HTTP transport so the GitHub OAuth token no longer gets interpolated into a child-process argv. The GitHub MCP endpoint is now configured directly as an HTTP server, so clients use native HTTP authentication instead of the sh -c launcher with mcp-remote. Reverting this change restores the previous configuration; no compile-time or state changes are involved, and OAuth credential rotation and contaminated-process termination were handled operationally.

Written for commit 9f81ea4. Summary will update on new commits.

Review in cubic

@shunkakinoki
shunkakinoki merged commit 537dc47 into main Sep 1, 2026
2 of 3 checks passed
@shunkakinoki
shunkakinoki deleted the fix/github-mcp-argv-safe branch September 1, 2026 02:38
@coderabbitai

coderabbitai Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Team

Run ID: 9e54caee-4199-4ab6-a8cc-14d926a59534

📥 Commits

Reviewing files that changed from the base of the PR and between 3886443 and 9f81ea4.

📒 Files selected for processing (1)
  • .ruler/mcp.json

Disabled knowledge base sources:

  • Linear integration is disabled

You can enable these sources in your CodeRabbit configuration.


📝 Walkthrough

Summary by CodeRabbit

  • Chores
    • Updated the GitHub integration to use a direct HTTP connection.
    • Simplified connection setup by removing local command-based authentication handling.

Walkthrough

The GitHub MCP server configuration now uses native HTTP transport with the GitHub Copilot MCP endpoint. The shell subprocess, mcp-remote invocation, and gh auth token header were removed.

Changes

GitHub MCP transport

Layer / File(s) Summary
Configure HTTP transport
.ruler/mcp.json
The GitHub MCP entry now uses type: "http" and the GitHub Copilot MCP URL. The shell command and bearer token handling were removed.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Poem

A rabbit hops where shell commands ran
HTTP carries the MCP plan
No token header, no subprocess flight
The endpoint now points straight and right
Ears up high, the config is bright

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/github-mcp-argv-safe

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant