Detect & migrate CLI flags a package removed across a major version (e.g. ssh-mcp v2 --password → SSH_MCP_PASSWORD) #88

Closed
opened 2026-08-11 11:58:40 -04:00 by the_og · 0 comments
Owner

Problem

Some MCP servers move credential flags off the command line across a major version, because CLI secrets are visible to any local user in /proc/<pid>/cmdline. A config written for the old version then fails hard on the new one. Real example (ssh-mcp v2.0.0):

Fatal error: Error: These flags were removed in v2:
  --password: Use the SSH_MCP_PASSWORD env var (or a per-profile SSH_MCP_<PROFILE>_PASSWORD).

The server never starts, and the fix (delete --password, add SSH_MCP_PASSWORD in env{} with the literal value) requires the user to decode the crash and know the exact replacement var name.

Relationship to #83

Complementary, not a duplicate. #83 offers a generic "secret arg → ${VAR} reference" conversion. This is package-aware: it knows the flag was removed and the exact env var the package now reads, and it writes the literal value into env{} — which is also the only form that works on Claude Desktop, since Desktop doesn't expand ${VAR} (BCC already warns about that). So ${VAR} alone would not have fixed the live Claude Desktop case that motivated this.

Proposed change

Data-driven registry + pure functions in bcc_core, plus a one-click fix in the editor:

  • FLAG_ENV_MIGRATIONS — per package: env (removed flag → replacement env var, auto-migratable) and removed (flags gone with no confirmed 1:1 env name, warn-only). Seeded with ssh-mcp (--password → SSH_MCP_PASSWORD; --sudoPassword/--suPassword/--disableSudo warn-only pending confirmed names).
  • detect_migratable_package(data) — matches the npm package from command/args (handles npx -y pkg, direct command, pkg@version, scoped names, path prefixes).
  • migrate_removed_flags(data) -> (new_data, notes) — moves the flag's value into env{} (both --flag value and --flag=value forms), drops the dead flag, never clobbers an existing env value, migrates a ${VAR} verbatim. No-op returns the same object.
  • removed_flag_warnings(data) / removed_flag_warning(data) — advisory lines covering auto-migratable and manual-only flags.
  • GUI: "Fix: move to environment variables" button + warning in the stdio server editor (mirrors the existing split-args / secret-in-args pattern), and a lint line in the main window so it's visible without opening the editor.

14 unit tests. Full suite green, ruff clean.

Branch feat/removed-flag-env-migration off main (PR to follow).

## Problem Some MCP servers move credential flags off the command line across a major version, because CLI secrets are visible to any local user in `/proc/<pid>/cmdline`. A config written for the old version then fails hard on the new one. Real example (`ssh-mcp` v2.0.0): ``` Fatal error: Error: These flags were removed in v2: --password: Use the SSH_MCP_PASSWORD env var (or a per-profile SSH_MCP_<PROFILE>_PASSWORD). ``` The server never starts, and the fix (delete `--password`, add `SSH_MCP_PASSWORD` in `env{}` with the literal value) requires the user to decode the crash and know the exact replacement var name. ## Relationship to #83 Complementary, not a duplicate. #83 offers a **generic** "secret arg → `${VAR}` reference" conversion. This is **package-aware**: it knows the flag was *removed* and the *exact* env var the package now reads, and it writes the **literal** value into `env{}` — which is also the only form that works on Claude Desktop, since Desktop doesn't expand `${VAR}` (BCC already warns about that). So `${VAR}` alone would not have fixed the live Claude Desktop case that motivated this. ## Proposed change Data-driven registry + pure functions in `bcc_core`, plus a one-click fix in the editor: - `FLAG_ENV_MIGRATIONS` — per package: `env` (removed flag → replacement env var, auto-migratable) and `removed` (flags gone with no confirmed 1:1 env name, warn-only). Seeded with `ssh-mcp` (`--password` → `SSH_MCP_PASSWORD`; `--sudoPassword`/`--suPassword`/`--disableSudo` warn-only pending confirmed names). - `detect_migratable_package(data)` — matches the npm package from command/args (handles `npx -y pkg`, direct command, `pkg@version`, scoped names, path prefixes). - `migrate_removed_flags(data) -> (new_data, notes)` — moves the flag's value into `env{}` (both `--flag value` and `--flag=value` forms), drops the dead flag, never clobbers an existing env value, migrates a `${VAR}` verbatim. No-op returns the same object. - `removed_flag_warnings(data)` / `removed_flag_warning(data)` — advisory lines covering auto-migratable and manual-only flags. - GUI: "Fix: move to environment variables" button + warning in the stdio server editor (mirrors the existing split-args / secret-in-args pattern), and a lint line in the main window so it's visible without opening the editor. 14 unit tests. Full suite green, ruff clean. Branch `feat/removed-flag-env-migration` off `main` (PR to follow).
the_og added the P1 label 2026-08-11 11:58:40 -04:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: the_og/better-claude-config#88