[Bug]: t3 code looks around all over my home folder and volumes
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 23k
- Forks
- 5.9k
- Avg merge
- 11h 14m
- Merged PRs (30d)
- 357
Description
Before submitting
- I searched existing issues and did not find a duplicate.
- I included enough detail to reproduce or investigate the problem.
Area
Not sure
Steps to reproduce
I have started the app on my mac, and added three providers, codex, claude and cursor. Then after a while MacOS asks me if T3 Code may access my ~/Documents folder, then it asks me if it may access my pictures. I tried setting "Add project starts in" to ~/src so maybe it wouldn't think my whole home directory is its playground, but that didn't help.
It also tries to access Dropbox / Google Drive volumes.
Expected behavior
I feel like this is very intrusive, and I don't see why it needs to go and traverse my whole computer without any indication of why it does that. It kind of makes me trust it less than any of the other coding tools, as it seems to "go out on its own", fiddling around.
Actual behavior
It fiddles around on my mac. Sure I can say "No" to those dialogs that MacOS asks me, but the question is why it should need access there, and why it triggered it, it must have tried to read those directories.
Impact
Minor bug or occasional failure
Version or commit
0.0.38 (c0995d2eaf8e)
Environment
macOS 15.6 (24G84)
Logs or stack traces
Screenshots, recordings, or supporting files
No response
Workaround
No response
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reproducing the behavior on macOS 15.6 with T3 Code 0.0.38 and the three listed providers, while observing which action triggers the Documents, Pictures, Dropbox, or Google Drive prompts. No files, tests, logs, or entry points are identified in the issue; done means locating the traversal trigger and preventing unrelated directories from being accessed without a clear reason.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- macos, typescript
- Domain
- desktop, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100