posit-dev / posit-dev/mcp-repl
Add sandbox mode with restricted file reads
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 70
- Forks
- 5
- PR merge metrics
- No merged PRs in 30d
Description
The sandbox should support file-read restrictions, not only restricted writes and restricted network.
When harness-specific sandbox settings are available, mcp-repl should detect them and match them. Otherwise, a sensible default would be workspace-read.
This should also leave room for a future mcp-repl configuration layer that exposes sandbox options more explicitly.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by tracing the existing restricted-write and restricted-network sandbox handling, then inspect how harness-specific settings are detected. Add matching file-read restrictions, use workspace-read when no harness settings are available, and leave a clear boundary for future mcp-repl sandbox configuration.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100