Some MCP servers move credential flags off the command line across a major version (CLI secrets are visible in /proc/<pid>/cmdline). A config written for the old version then crashes on startup. Real case that motivated this — ssh-mcp v2.0.0:
Fatal error: Error: These flags were removed in v2:
--password: Use the SSH_MCP_PASSWORD env var (or a per-profile SSH_MCP_<PROFILE>_PASSWORD).
This teaches BCC to recognise that shape, warn about it, and one-click fix it by lifting the value out of args into env{} under the exact name the package now reads.
Complementary. #83 is a generic "secret arg → ${VAR} reference" conversion. This is package-aware: it knows the flag was removed and the exact env var, and writes the literal value into env{} — the only form Claude Desktop honours (it doesn't expand ${VAR}), so ${VAR} alone wouldn't fix the Desktop server this came from.
Changes
bcc_core.py:
FLAG_ENV_MIGRATIONS registry — per package, an env map (removed flag → replacement var, auto-migratable) and a removed map (gone, no confirmed 1:1 env name, warn-only). Seeded with ssh-mcp: --password → SSH_MCP_PASSWORD auto; --sudoPassword/--suPassword/--disableSudo warn-only pending confirmed names.
detect_migratable_package — resolves the npm package from command/args (npx -y pkg, direct command, pkg@version, scoped names, path prefixes).
migrate_removed_flags(data) -> (new_data, notes) — pure; handles --flag value and --flag=value, never clobbers an existing env value, migrates a ${VAR} verbatim, drops the args key if it empties, returns the same object on no-op.
"Fix: move to environment variables" button + warning in the stdio server editor, mirroring the existing split-args / secret-in-args pattern; the button only shows when something is actually auto-migratable.
A removed_flag_warnings line folded into the main-window lint pass so it surfaces without opening the editor.
Tests
14 new unit tests in tests/test_core.py (detection incl. version/scope/path forms, both arg spellings, env-merge, no-clobber, ${VAR} passthrough, no-op identity, unknown-package no-op, warn coverage, and the exact ssh-membermatters end-to-end shape). Full suite green, ruff check + ruff format --check clean.
Note for review
Only --password → SSH_MCP_PASSWORD is in the auto-migrate map because that's the one confirmed by the v2 error text. --sudoPassword/--suPassword are warn-only until their exact env names are confirmed from the ssh-mcp README — add them to the env map when verified and they become one-click too.
Closes #88.
## What & why
Some MCP servers move credential flags off the command line across a major version (CLI secrets are visible in `/proc/<pid>/cmdline`). A config written for the old version then crashes on startup. Real case that motivated this — `ssh-mcp` v2.0.0:
```
Fatal error: Error: These flags were removed in v2:
--password: Use the SSH_MCP_PASSWORD env var (or a per-profile SSH_MCP_<PROFILE>_PASSWORD).
```
This teaches BCC to recognise that shape, warn about it, and one-click fix it by lifting the value out of `args` into `env{}` under the exact name the package now reads.
## Relationship to #83
Complementary. #83 is a **generic** "secret arg → `${VAR}` reference" conversion. This is **package-aware**: it knows the flag was *removed* and the *exact* env var, and writes the **literal** value into `env{}` — the only form Claude Desktop honours (it doesn't expand `${VAR}`), so `${VAR}` alone wouldn't fix the Desktop server this came from.
## Changes
`bcc_core.py`:
- `FLAG_ENV_MIGRATIONS` registry — per package, an `env` map (removed flag → replacement var, auto-migratable) and a `removed` map (gone, no confirmed 1:1 env name, warn-only). Seeded with `ssh-mcp`: `--password` → `SSH_MCP_PASSWORD` auto; `--sudoPassword`/`--suPassword`/`--disableSudo` warn-only pending confirmed names.
- `detect_migratable_package` — resolves the npm package from command/args (`npx -y pkg`, direct command, `pkg@version`, scoped names, path prefixes).
- `migrate_removed_flags(data) -> (new_data, notes)` — pure; handles `--flag value` and `--flag=value`, never clobbers an existing env value, migrates a `${VAR}` verbatim, drops the args key if it empties, returns the same object on no-op.
- `removed_flag_warnings` / `removed_flag_warning` — advisory lines (auto-migratable + manual-only).
`bcc.py`:
- "Fix: move to environment variables" button + warning in the stdio server editor, mirroring the existing split-args / secret-in-args pattern; the button only shows when something is actually auto-migratable.
- A `removed_flag_warnings` line folded into the main-window lint pass so it surfaces without opening the editor.
## Tests
14 new unit tests in `tests/test_core.py` (detection incl. version/scope/path forms, both arg spellings, env-merge, no-clobber, `${VAR}` passthrough, no-op identity, unknown-package no-op, warn coverage, and the exact `ssh-membermatters` end-to-end shape). Full suite green, `ruff check` + `ruff format --check` clean.
## Note for review
Only `--password` → `SSH_MCP_PASSWORD` is in the auto-migrate map because that's the one confirmed by the v2 error text. `--sudoPassword`/`--suPassword` are warn-only until their exact env names are confirmed from the ssh-mcp README — add them to the `env` map when verified and they become one-click too.
the_og
added the P1 label 2026-08-11 12:02:32 -04:00
ssh-mcp v2 removed --password from the command line and reads
SSH_MCP_PASSWORD instead, so an old config crashes on startup. Add a
data-driven FLAG_ENV_MIGRATIONS registry plus detect_migratable_package,
migrate_removed_flags and removed_flag_warnings in bcc_core, and a
'Fix: move to environment variables' one-click action + warning in the
stdio server editor, with a matching main-window lint line. The literal
value lands in env{} (the only form Claude Desktop honours). 14 tests.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Closes #88.
What & why
Some MCP servers move credential flags off the command line across a major version (CLI secrets are visible in
/proc/<pid>/cmdline). A config written for the old version then crashes on startup. Real case that motivated this —ssh-mcpv2.0.0:This teaches BCC to recognise that shape, warn about it, and one-click fix it by lifting the value out of
argsintoenv{}under the exact name the package now reads.Relationship to #83
Complementary. #83 is a generic "secret arg →
${VAR}reference" conversion. This is package-aware: it knows the flag was removed and the exact env var, and writes the literal value intoenv{}— the only form Claude Desktop honours (it doesn't expand${VAR}), so${VAR}alone wouldn't fix the Desktop server this came from.Changes
bcc_core.py:FLAG_ENV_MIGRATIONSregistry — per package, anenvmap (removed flag → replacement var, auto-migratable) and aremovedmap (gone, no confirmed 1:1 env name, warn-only). Seeded withssh-mcp:--password→SSH_MCP_PASSWORDauto;--sudoPassword/--suPassword/--disableSudowarn-only pending confirmed names.detect_migratable_package— resolves the npm package from command/args (npx -y pkg, direct command,pkg@version, scoped names, path prefixes).migrate_removed_flags(data) -> (new_data, notes)— pure; handles--flag valueand--flag=value, never clobbers an existing env value, migrates a${VAR}verbatim, drops the args key if it empties, returns the same object on no-op.removed_flag_warnings/removed_flag_warning— advisory lines (auto-migratable + manual-only).bcc.py:removed_flag_warningsline folded into the main-window lint pass so it surfaces without opening the editor.Tests
14 new unit tests in
tests/test_core.py(detection incl. version/scope/path forms, both arg spellings, env-merge, no-clobber,${VAR}passthrough, no-op identity, unknown-package no-op, warn coverage, and the exactssh-membermattersend-to-end shape). Full suite green,ruff check+ruff format --checkclean.Note for review
Only
--password→SSH_MCP_PASSWORDis in the auto-migrate map because that's the one confirmed by the v2 error text.--sudoPassword/--suPasswordare warn-only until their exact env names are confirmed from the ssh-mcp README — add them to theenvmap when verified and they become one-click too.ssh-mcp v2 removed --password from the command line and reads SSH_MCP_PASSWORD instead, so an old config crashes on startup. Add a data-driven FLAG_ENV_MIGRATIONS registry plus detect_migratable_package, migrate_removed_flags and removed_flag_warnings in bcc_core, and a 'Fix: move to environment variables' one-click action + warning in the stdio server editor, with a matching main-window lint line. The literal value lands in env{} (the only form Claude Desktop honours). 14 tests.