Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

feat(grok): let a t3-started Grok session run with only the MCP servers t3 declares

未关闭
#12,914 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
55/100
Issue 类型
功能
描述清晰度
基本清楚
活跃度
活跃
技术栈
typescript
领域
api, backend, security

调研方向

Start at t3's Grok ACP session/new launch path and trace how the declared mcpServers reach the Grok CLI. Compare the isolated-config-root option with documenting inherited user servers, then verify that a session exposes only the declared servers or that clients can fail closed when it cannot be scoped.

由索引模型根据 Issue 内容生成。

描述

documentation enhancement upstream via-triage
What I'm building

An external orchestrator that starts t3 threads for automated work. Some of those threads
must run with a narrow MCP surface: a worker that reaches exactly one server and provably
not the operator's others — production database servers among them.

Problem

For Claude Code, t3 passes the server set per process (--mcp-config <inline JSON>), and
Claude Code additionally offers --strict-mcp-config to suppress inherited configuration.
For Codex, t3 passes -c mcp_servers.<name>..... For Grok there is no equivalent: t3 starts
the session over ACP and session/new carries mcpServers, but the Grok CLI (1.0.40)
admits that list on top of what it already has (admit_client_mcp_servers) instead of
substituting it.

Everything else in the Grok CLI that looks like an answer is not one: a project-level
.grok/config.toml replaces entries by name only, disabled_mcp_servers is a user-layer
key, and there is no --strict-mcp-config equivalent.

Net effect: a Grok session started by t3 inherits the user's full MCP server set, including
servers imported through [compat.claude] / [compat.cursor]. A client can neither scope
that session nor verify that it is scoped.

Workaround, and why it is not enough

[compat.claude] mcps = false + [compat.cursor] mcps = false in ~/.grok/config.toml.
Verified at both layers: config (every compat-imported server disabled) and live session
(connected set becomes t3-code and nothing else). That is acceptable on a machine
dedicated to t3, but it is machine-global rather than per session, and it disables the
compat import for anyone who also uses Grok interactively.

Ask

Either (a) spawn Grok with an isolated config root — a t3-owned GROK_HOME — so the session
sees only what t3 declares, or (b) if the strictness has to come from the Grok CLI itself,
document that t3-started Grok sessions inherit user-level MCP servers, so clients that need
a scoped session can fail closed instead of assuming.

主要语言
TypeScript
星标
24.8k
派生
6.4k
平均合并
8 小时 34 分钟
30 天内合并 PR
243

环境准备

在 Codespaces 中打开

在浏览器里用你自己的 GitHub 账号启动这个项目的开发容器。

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

pingdotgg/t3code 的其他 Issue

查看 pingdotgg/t3code 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。