维护者确认 · #2936 fix(orca): guide safe Code Mode text arguments
Open
- Dominant language
- TypeScript
- Stars
- 2.7k
- Forks
- 395
- Avg merge
- 21h 48m
- Merged PRs (30d)
- 776
Description
## 确认类别
security(Orca Code Mode 的自由文本参数注入治理)
## 触发原因
修改 packages/lizi-mcps 的 Code Mode 工具参数校验——涉及安全约束变更。
## 需要维护者确认
1. 新增的校验规则是否合理(白名单口径而非黑名单)
2. 是否有已知业务场景会被误拦
## 如何放行
在 PR 上 Approve 即可;如需作者修改请 Request Changes。
---
关联 PR:#2936(作者 @ZJPex);本 issue 由 review-pr 流程自动创建,用于先讨论该 PR 涉及的安全敏感改动,维护者确认后 PR 会恢复推进。
Contributor guide
Research direction
Start by reviewing PR #2936 and the Code Mode tool-parameter validation changes under packages/lizi-mcps. Check the proposed whitelist rules against known business scenarios and assess whether they introduce false positives or preserve the stated security constraint. Done means a maintainer can approve the PR or request specific changes.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- typescript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100