feat(grok): let a t3-started Grok session run with only the MCP servers t3 declares
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 55/100
- Issue 类型
- 功能
- 描述清晰度
- 基本清楚
- 活跃度
- 活跃
- 技术栈
- typescript
调研方向
Start at t3's Grok ACP session/new launch path and trace how the declared mcpServers reach the Grok CLI. Compare the isolated-config-root option with documenting inherited user servers, then verify that a session exposes only the declared servers or that clients can fail closed when it cannot be scoped.
由索引模型根据 Issue 内容生成。
描述
What I'm building
An external orchestrator that starts t3 threads for automated work. Some of those threads
must run with a narrow MCP surface: a worker that reaches exactly one server and provably
not the operator's others — production database servers among them.
Problem
For Claude Code, t3 passes the server set per process (--mcp-config <inline JSON>), and
Claude Code additionally offers --strict-mcp-config to suppress inherited configuration.
For Codex, t3 passes -c mcp_servers.<name>..... For Grok there is no equivalent: t3 starts
the session over ACP and session/new carries mcpServers, but the Grok CLI (1.0.40)
admits that list on top of what it already has (admit_client_mcp_servers) instead of
substituting it.
Everything else in the Grok CLI that looks like an answer is not one: a project-level
.grok/config.toml replaces entries by name only, disabled_mcp_servers is a user-layer
key, and there is no --strict-mcp-config equivalent.
Net effect: a Grok session started by t3 inherits the user's full MCP server set, including
servers imported through [compat.claude] / [compat.cursor]. A client can neither scope
that session nor verify that it is scoped.
Workaround, and why it is not enough
[compat.claude] mcps = false + [compat.cursor] mcps = false in ~/.grok/config.toml.
Verified at both layers: config (every compat-imported server disabled) and live session
(connected set becomes t3-code and nothing else). That is acceptable on a machine
dedicated to t3, but it is machine-global rather than per session, and it disables the
compat import for anyone who also uses Grok interactively.
Ask
Either (a) spawn Grok with an isolated config root — a t3-owned GROK_HOME — so the session
sees only what t3 declares, or (b) if the strictness has to come from the Grok CLI itself,
document that t3-started Grok sessions inherit user-level MCP servers, so clients that need
a scoped session can fail closed instead of assuming.
- 主要语言
- TypeScript
- 星标
- 24.8k
- 派生
- 6.4k
- 平均合并
- 8 小时 34 分钟
- 30 天内合并 PR
- 243
环境准备
在浏览器里用你自己的 GitHub 账号启动这个项目的开发容器。
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
pingdotgg/t3code 的其他 Issue
-
[Bug]: Dead-key apostrophe inserts extra quotes in the composer可能已有人在做 关联的 PR 仍在进行中或已合并。 未关闭bug via-triage
难度 2/5 1-3 小时 新手友好度 82/100
pingdotgg/t3code#16859 · 1 条评论 ·
维护者通常 1 天内回复
-
bug via-triage
难度 2/5 1-3 小时 新手友好度 72/100
pingdotgg/t3code#16822 · 1 条评论 ·
维护者通常 1 天内回复
-
bug via-triage
难度 2/5 1-3 小时 新手友好度 72/100
pingdotgg/t3code#16821 · 1 条评论 ·
维护者通常 1 天内回复
-
bug via-triage
难度 2/5 1-3 小时 新手友好度 66/100
pingdotgg/t3code#16810 · 2 条评论 ·
维护者通常 1 天内回复
-
[Bug]: Antigravity turns fail on NixOS: embedded Python can't verify TLS (empty CA store) -> 502未关闭bug via-triage
难度 2/5 1-3 小时 新手友好度 78/100
pingdotgg/t3code#16742 · 1 条评论 ·
维护者通常 1 天内回复
相似的 Issue
-
DB-plane provider_chat_options.* is accepted by config set but never merged into the loaded config未关闭
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复
-
Bump Firebase JS SDK (12.19.0 → 13.0.0)可能已有人在做 @SelaseKay 今天认领。 未关闭Needs Attention type: enhancement
难度 2/5 1-3 小时 新手友好度 75/100
invertase/react-native-firebase#9364 · 1 条评论 ·
维护者通常 1 天内回复
-
enhancement
难度 1/5 1 小时以内 新手友好度 85/100
cloudflare/mcp#271 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 82/100
维护者通常 4 天内回复
-
e2e-failure ready-to-code
难度 2/5 1-3 小时 新手友好度 78/100
redhat-developer/rhdh-plugin-export-overlays#4261 · 1 条评论 ·
维护者通常 1 天内回复