Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[feat] keep project MCP configs with resolved tokens out of git

Open
#882 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
55/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Active
Tech stack
git, typescript
Domain
cli, devtools, security

Research direction

Start by tracing the project MCP config reconciliation and buildSelfModeGitignore, then inspect the existing doctor and uninstall flows. Use the single-repo fixture from #879 and git status to verify resolved-token configs are locally excluded, doctor reports unsafe tracked paths, and uninstall removes only the entries teamai added.

Written by the indexing model from the issue text.

Description

enhancement

Problem

Project-scope MCP configs hold resolved tokens in plaintext inside the business repo's working tree, and nothing keeps git away from them.

<business repo>/
├── .mcp.json            "Authorization": "Bearer ghp_…"     ?? untracked, not ignored
├── .cursor/mcp.json     …
├── .codex/config.toml   …
└── .teamai/.gitignore   covers teamai state only (buildSelfModeGitignore), not these

One git add -A commits the token. Today the only guard is a docs warning (docs/usage-guide.md, MCP Secrets: "add them to .gitignore"). Affects every project scope that receives an MCP server with a ${VAR}, single-repo mode included. #875 raises the stakes: those values become members' personal tokens.

Proposed Solution

When teamai writes a project-scope MCP config that contains a resolved ${VAR}, add its path to the repo's .git/info/exclude. Local to the clone, nothing committed, idempotent; uninstall removes the lines it added.

 reconcile project MCP config
   write .mcp.json (0600)
+  if it carries a resolved ${VAR} and git doesn't ignore it already
+    append ".mcp.json" to .git/info/exclude   (marker comment, like the profile block)

doctor reports a project MCP config with a resolved value that git would track.

Alternatives Considered

  • Write the paths into the committed .gitignore. Changes a file the team owns, on every member's machine; a team that commits a token-free .mcp.json on purpose would lose it.
  • Only keep the docs warning. What we have; it relies on every member reading it.
  • Keep ${VAR} placeholders in the config. Rejected in the docs: GUI-launched tools don't inherit the shell, so the server gets an empty token.

Additional Context

Found while implementing #879 (ticket 04's real-CLI run: git status shows ?? .mcp.json holding the fixture token in single-repo mode). Pre-existing on main; not part of #880.

Dominant language
TypeScript
Stars
5k
Forks
376
Avg merge
13h 21m
Merged PRs (30d)
288

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from Tencent/teamai-cli

All issues in Tencent/teamai-cli

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.