Skip to content

Update Sent MCP workflows and resolve marketplace security findings - #15

Merged
sent-dm merged 1 commit into
mainfrom
codex/sent-mcp-update-security
Oct 2, 2026
Merged

sent-dm merged 1 commit into
mainfrom
codex/sent-mcp-update-security

Conversation

@sent-dm

@sent-dm sent-dm commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

Updates Sent to v0.2.0 with 27 MCP tools and 21 skills, including SMS compliance, authorized feedback, Sender Profile operations, scheduled template sends, and revised account and analytics guidance. Regenerates the portable, Codex, and Claude packages from their canonical sources.

Resolves the four code/security review findings: migration inventory reports omit source excerpts, scans refuse symbolic links and non-regular files, an independent policy prevents confirmation requirements from being downgraded through metadata, and portable/Codex listings share complete support and legal URLs. Documents local utility behavior and adds regression checks.

Validation: canonical package validation and generated adapter parity; 30 utility tests, 14 contract tests, 6 freshness-monitor simulation tests; all 35 unsafe validation cases rejected; both strict Claude validations; scanner self-test; clean whitespace checks.

Live server authorization and retention are outside the verified scope. This change does not certify marketplace approval.

@sent-dm
sent-dm merged commit 5ee8de1 into main Oct 2, 2026
2 checks passed

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reviewed this PR and didn't find any bugs. Beyond the reported findings, I also checked the new REQUIRED_CONFIRMATION_TOOLS / independent-safety-policy enforcement in scripts/repository_metadata.py: it correctly pins owner/mutation/confirmation for the eight listed mutating tools, but the blanket "every state_changing/destructive tool needs confirmation" check (line 134) carves out numbers.lookup by name rather than through policy data, matching its state_changing/confirmation_required: false entry in public-surface.json — a deliberate, narrow exemption rather than a bug. Given the size of this change (94 files, large duplication across five package mirrors) and that it touches the confirmation/permission policy for destructive MCP tools, a human look is still worthwhile.

Extended reasoning...

The diff updates Sent MCP plugin skills, validation scripts, and metadata across five near-duplicate tree locations (skills/, scripts/, claude-plugins/sent, packages/sent, plugins/sent), including a new independent safety policy in scripts/repository_metadata.py that enforces confirmation requirements for state-changing/destructive MCP tools. This touches permission-adjacent logic (which tools require user confirmation before mutating/destructive actions) even though it is static metadata validation rather than live authorization code. No injection or data-exposure issues were found; the one candidate issue (a hardcoded numbers.lookup exemption from the confirmation rule) was examined and appears to be an intentional, narrow carve-out rather than a bug. Given the large size (94 files) and security-adjacent surface, I'm deferring rather than approving.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant