makecindy / makecindy/cindy

维护者确认 · #2936 fix(orca): guide safe Code Mode text arguments

Open
#2,955 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
2.7k
Forks
395
Avg merge
21h 48m
Merged PRs (30d)
776

Description

## 确认类别

security(Orca Code Mode 的自由文本参数注入治理)

## 触发原因

修改 packages/lizi-mcps 的 Code Mode 工具参数校验——涉及安全约束变更。

## 需要维护者确认

1. 新增的校验规则是否合理(白名单口径而非黑名单)
2. 是否有已知业务场景会被误拦

## 如何放行

在 PR 上 Approve 即可;如需作者修改请 Request Changes。

---
关联 PR:#2936(作者 @ZJPex);本 issue 由 review-pr 流程自动创建,用于先讨论该 PR 涉及的安全敏感改动,维护者确认后 PR 会恢复推进。

Contributor guide

Open the contributing guide

Research direction

Start by reviewing PR #2936 and the Code Mode tool-parameter validation changes under packages/lizi-mcps. Check the proposed whitelist rules against known business scenarios and assess whether they introduce false positives or preserve the stated security constraint. Done means a maintainer can approve the PR or request specific changes.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.