[feat] keep project MCP configs with resolved tokens out of git
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 55/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- git, typescript
Research direction
Start by tracing the project MCP config reconciliation and buildSelfModeGitignore, then inspect the existing doctor and uninstall flows. Use the single-repo fixture from #879 and git status to verify resolved-token configs are locally excluded, doctor reports unsafe tracked paths, and uninstall removes only the entries teamai added.
Written by the indexing model from the issue text.
Description
Problem
Project-scope MCP configs hold resolved tokens in plaintext inside the business repo's working tree, and nothing keeps git away from them.
<business repo>/
├── .mcp.json "Authorization": "Bearer ghp_…" ?? untracked, not ignored
├── .cursor/mcp.json …
├── .codex/config.toml …
└── .teamai/.gitignore covers teamai state only (buildSelfModeGitignore), not these
One git add -A commits the token. Today the only guard is a docs warning (docs/usage-guide.md, MCP Secrets: "add them to .gitignore"). Affects every project scope that receives an MCP server with a ${VAR}, single-repo mode included. #875 raises the stakes: those values become members' personal tokens.
Proposed Solution
When teamai writes a project-scope MCP config that contains a resolved ${VAR}, add its path to the repo's .git/info/exclude. Local to the clone, nothing committed, idempotent; uninstall removes the lines it added.
reconcile project MCP config
write .mcp.json (0600)
+ if it carries a resolved ${VAR} and git doesn't ignore it already
+ append ".mcp.json" to .git/info/exclude (marker comment, like the profile block)
doctor reports a project MCP config with a resolved value that git would track.
Alternatives Considered
- Write the paths into the committed
.gitignore. Changes a file the team owns, on every member's machine; a team that commits a token-free.mcp.jsonon purpose would lose it. - Only keep the docs warning. What we have; it relies on every member reading it.
- Keep
${VAR}placeholders in the config. Rejected in the docs: GUI-launched tools don't inherit the shell, so the server gets an empty token.
Additional Context
Found while implementing #879 (ticket 04's real-CLI run: git status shows ?? .mcp.json holding the fixture token in single-repo mode). Pre-existing on main; not part of #880.
- Dominant language
- TypeScript
- Stars
- 5k
- Forks
- 376
- Avg merge
- 13h 21m
- Merged PRs (30d)
- 288
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from Tencent/teamai-cli
-
bug help wanted
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Tencent/teamai-cli#893 ·
Maintainers usually reply within 1 day
-
bug help wanted
Difficulty 4/5 3-5 days Newbie friendliness 65/100
Tencent/teamai-cli#894 · 1 comment ·
Maintainers usually reply within 1 day
-
bug help wanted
Difficulty 3/5 1-2 days Newbie friendliness 74/100
Tencent/teamai-cli#892 ·
Maintainers usually reply within 1 day
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
Tencent/teamai-cli#884 ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 38/100
Tencent/teamai-cli#883 ·
Maintainers usually reply within 1 day
All issues in Tencent/teamai-cli
Similar issues
-
documentation
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
inu-appcenter/memorIN-frontend#106 ·
Maintainers usually reply within 1 day
-
kind/bug
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Maintainers usually reply within 7 days
-
[Bug] @deck.gl/arcgis dist import resolves to unpublished @deck.gl/core source path (9.3.11, 9.4.0)Open
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
CSCfi/sd-search-ui#145 ·
Maintainers usually reply within 1 day
-
Add: Cbeebies pl SDOpencheck:passed streams:add
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
Maintainers usually reply within 1 day