Some MCP servers move credential flags off the command line across a major version, because CLI secrets are visible to any local user in /proc/<pid>/cmdline. A config written for the old version then fails hard on the new one. Real example (ssh-mcp v2.0.0):
Fatal error: Error: These flags were removed in v2:
--password: Use the SSH_MCP_PASSWORD env var (or a per-profile SSH_MCP_<PROFILE>_PASSWORD).
The server never starts, and the fix (delete --password, add SSH_MCP_PASSWORD in env{} with the literal value) requires the user to decode the crash and know the exact replacement var name.
Complementary, not a duplicate. #83 offers a generic "secret arg → ${VAR} reference" conversion. This is package-aware: it knows the flag was removed and the exact env var the package now reads, and it writes the literal value into env{} — which is also the only form that works on Claude Desktop, since Desktop doesn't expand ${VAR} (BCC already warns about that). So ${VAR} alone would not have fixed the live Claude Desktop case that motivated this.
Proposed change
Data-driven registry + pure functions in bcc_core, plus a one-click fix in the editor:
FLAG_ENV_MIGRATIONS — per package: env (removed flag → replacement env var, auto-migratable) and removed (flags gone with no confirmed 1:1 env name, warn-only). Seeded with ssh-mcp (--password → SSH_MCP_PASSWORD; --sudoPassword/--suPassword/--disableSudo warn-only pending confirmed names).
detect_migratable_package(data) — matches the npm package from command/args (handles npx -y pkg, direct command, pkg@version, scoped names, path prefixes).
migrate_removed_flags(data) -> (new_data, notes) — moves the flag's value into env{} (both --flag value and --flag=value forms), drops the dead flag, never clobbers an existing env value, migrates a ${VAR} verbatim. No-op returns the same object.
GUI: "Fix: move to environment variables" button + warning in the stdio server editor (mirrors the existing split-args / secret-in-args pattern), and a lint line in the main window so it's visible without opening the editor.
14 unit tests. Full suite green, ruff clean.
Branch feat/removed-flag-env-migration off main (PR to follow).
## Problem
Some MCP servers move credential flags off the command line across a major version, because CLI secrets are visible to any local user in `/proc/<pid>/cmdline`. A config written for the old version then fails hard on the new one. Real example (`ssh-mcp` v2.0.0):
```
Fatal error: Error: These flags were removed in v2:
--password: Use the SSH_MCP_PASSWORD env var (or a per-profile SSH_MCP_<PROFILE>_PASSWORD).
```
The server never starts, and the fix (delete `--password`, add `SSH_MCP_PASSWORD` in `env{}` with the literal value) requires the user to decode the crash and know the exact replacement var name.
## Relationship to #83
Complementary, not a duplicate. #83 offers a **generic** "secret arg → `${VAR}` reference" conversion. This is **package-aware**: it knows the flag was *removed* and the *exact* env var the package now reads, and it writes the **literal** value into `env{}` — which is also the only form that works on Claude Desktop, since Desktop doesn't expand `${VAR}` (BCC already warns about that). So `${VAR}` alone would not have fixed the live Claude Desktop case that motivated this.
## Proposed change
Data-driven registry + pure functions in `bcc_core`, plus a one-click fix in the editor:
- `FLAG_ENV_MIGRATIONS` — per package: `env` (removed flag → replacement env var, auto-migratable) and `removed` (flags gone with no confirmed 1:1 env name, warn-only). Seeded with `ssh-mcp` (`--password` → `SSH_MCP_PASSWORD`; `--sudoPassword`/`--suPassword`/`--disableSudo` warn-only pending confirmed names).
- `detect_migratable_package(data)` — matches the npm package from command/args (handles `npx -y pkg`, direct command, `pkg@version`, scoped names, path prefixes).
- `migrate_removed_flags(data) -> (new_data, notes)` — moves the flag's value into `env{}` (both `--flag value` and `--flag=value` forms), drops the dead flag, never clobbers an existing env value, migrates a `${VAR}` verbatim. No-op returns the same object.
- `removed_flag_warnings(data)` / `removed_flag_warning(data)` — advisory lines covering auto-migratable and manual-only flags.
- GUI: "Fix: move to environment variables" button + warning in the stdio server editor (mirrors the existing split-args / secret-in-args pattern), and a lint line in the main window so it's visible without opening the editor.
14 unit tests. Full suite green, ruff clean.
Branch `feat/removed-flag-env-migration` off `main` (PR to follow).
the_og
added the P1 label 2026-08-11 11:58:40 -04:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Problem
Some MCP servers move credential flags off the command line across a major version, because CLI secrets are visible to any local user in
/proc/<pid>/cmdline. A config written for the old version then fails hard on the new one. Real example (ssh-mcpv2.0.0):The server never starts, and the fix (delete
--password, addSSH_MCP_PASSWORDinenv{}with the literal value) requires the user to decode the crash and know the exact replacement var name.Relationship to #83
Complementary, not a duplicate. #83 offers a generic "secret arg →
${VAR}reference" conversion. This is package-aware: it knows the flag was removed and the exact env var the package now reads, and it writes the literal value intoenv{}— which is also the only form that works on Claude Desktop, since Desktop doesn't expand${VAR}(BCC already warns about that). So${VAR}alone would not have fixed the live Claude Desktop case that motivated this.Proposed change
Data-driven registry + pure functions in
bcc_core, plus a one-click fix in the editor:FLAG_ENV_MIGRATIONS— per package:env(removed flag → replacement env var, auto-migratable) andremoved(flags gone with no confirmed 1:1 env name, warn-only). Seeded withssh-mcp(--password→SSH_MCP_PASSWORD;--sudoPassword/--suPassword/--disableSudowarn-only pending confirmed names).detect_migratable_package(data)— matches the npm package from command/args (handlesnpx -y pkg, direct command,pkg@version, scoped names, path prefixes).migrate_removed_flags(data) -> (new_data, notes)— moves the flag's value intoenv{}(both--flag valueand--flag=valueforms), drops the dead flag, never clobbers an existing env value, migrates a${VAR}verbatim. No-op returns the same object.removed_flag_warnings(data)/removed_flag_warning(data)— advisory lines covering auto-migratable and manual-only flags.14 unit tests. Full suite green, ruff clean.
Branch
feat/removed-flag-env-migrationoffmain(PR to follow).