forked from bchanot/claude
job7 capitalize: BDR-057, BDR-026 update, LRN-108, journal
BDR-057: secrets by reference not by value; redact at capture, not just at
rest. Documents the two-part job7 posture (MCP ${VAR} expansion + rtk-rewrite
env-dump redaction) and flags the unreconciled contradiction with job6's
same-day (wrong) finding that ${VAR} expansion was unsupported at user scope.
BDR-026 updated: the backup-vector incident (2026-07-02) is closed at the
source rather than by repeated scrubbing — every native auto-backup taken
while the live file held the plaintext value was a fresh leak, so scrubbing
existing backups alone would have recurred forever.
LRN-108: `claude mcp add --env KEY=value` writes the value literally —
double- vs single-quoting around `${VAR}` is the entire difference between
a reference and a plaintext-forever config. The natural way to type the
flag (bash-expand it first) is exactly the trap.
Also refreshed .audit/scan-secrets-claude-home.json to the post-purge state
(15 residual hits, down from 18 pre-D).
This commit is contained in:
@@ -1092,3 +1092,13 @@ rules:
|
||||
- **context**: `.audit/job6-report.md` "Incident (contained)" section; explorer-C.md redacted post-incident; caught before job6's execution phase, contained to scratchpad only.
|
||||
- **future application**: any read-only/no-execute subagent mandate that touches config or env files must explicitly ban copying a secret's VALUE into agent output/scratch, not just ban editing/deleting. Phrase the mandate as "reference by name/location, never paste the value" — when auditing MCP/env config, prefer `jq 'del(.. | .env?)'`-style filtering (already BDR-026 practice) over raw `cat`.
|
||||
- **cousin**: [[BDR-026]] (secrets have copies, protect/audit them all), [[LRN-105]] (explorer no-execute mandate, the sibling rule this extends).
|
||||
|
||||
---
|
||||
|
||||
## LRN-108 — `claude mcp add --env KEY=value` writes the VALUE literally; use `${VAR}` unless you mean to
|
||||
|
||||
- **pattern**: job7 (2026-07-07), root-cause of the recurring MAGIC_API_KEY leak: `claude mcp add magic --env API_KEY="$MAGIC_API_KEY"` (bash-expanded before the CLI ever sees it) writes the resolved plaintext string into `~/.claude.json`/`.mcp.json` — there is no `mcp add` flag that stores a reference instead. Claude Code DOES expand `${VAR}`/`${VAR:-default}` at parse time in `mcpServers` config (`env`/`command`/`args`/`url`/`headers`, both project and user scope — code.claude.com/docs/en/mcp.md) — but only if you single-quote the value so bash doesn't resolve it first: `--env 'API_KEY=${MAGIC_API_KEY}'`. Single vs. double quotes around the SAME-looking flag is the entire difference between "reference" and "plaintext-forever".
|
||||
- **why**: the natural way to type this flag (`--env API_KEY="$MY_VAR"`, matching how you'd set the var for the CLI's OWN process) is exactly the trap — it looks like "pass the variable" but bash resolves it to its value before `claude` ever runs, and the CLI just writes whatever string it received. Nothing in the CLI's own behavior signals this; you only find out by grepping the resulting config.
|
||||
- **context**: `lib/toggle-external.sh:191` had this exact double-quoted form since BDR-025/026; it materialized the key into `~/.claude.json` (2026-07-02 incident) and kept re-leaking into every native auto-backup taken afterward (5-file rotating ring buffer, plaintext each time) until fixed at the source.
|
||||
- **future application**: adding ANY MCP server with a secret via `claude mcp add --env`, single-quote the value using `${VAR}` syntax, never double-quote/bash-expand it. The var still has to exist in the environment of the process that starts `claude` — don't solve that with a blanket `export` in `~/.bashrc` (broadens exposure to every subprocess); scope it with a wrapper function that sources the secret into a subshell before `exec`ing the real binary (see `~/.bashrc`'s `claude()` function, [[BDR-057]]).
|
||||
- **cousin**: [[BDR-026]] (canonical vault + copies), [[BDR-057]] (secrets-by-reference decision this trap motivated), [[LRN-107]] (same job family, don't-copy-the-value discipline).
|
||||
|
||||
Reference in New Issue
Block a user