Before submitting
Area
apps/server
Steps to reproduce
- Start T3 Code 0.0.45 (desktop app on Linux; server on
127.0.0.1:3773).
- Open a thread that uses the Claude provider.
- From any process running as the same user, list process arguments:
ps -eo args.
Expected behavior
The bearer credential for the T3 Code MCP server does not appear in any process's argv. For example, it is passed through a file with mode 0600, an inherited file descriptor, or an environment variable.
Actual behavior
The spawned claude process receives the MCP configuration inline:
--mcp-config {"mcpServers":{"t3-code":{"type":"http","url":"http://127.0.0.1:3773/mcp","headers":{"Authorization":"Bearer <redacted>"}}}}
The token is readable in /proc/<pid>/cmdline and in ps output for as long as the session runs.
Impact
Any local process running as the same user, and any tool that captures process lists (monitoring, crash reports, shell history of a ps paste, screenshots), can read a credential that authorizes calls to the T3 Code MCP endpoint. The exposure is local and limited to the same user, but the token ends up in places where people don't expect secrets.
Version or commit
0.0.45
Environment
Arch-based Linux, t3code-bin package, desktop app, Claude provider.
Logs or stack traces
None; observed through process arguments.
Before submitting
Area
apps/server
Steps to reproduce
127.0.0.1:3773).ps -eo args.Expected behavior
The bearer credential for the T3 Code MCP server does not appear in any process's argv. For example, it is passed through a file with mode 0600, an inherited file descriptor, or an environment variable.
Actual behavior
The spawned
claudeprocess receives the MCP configuration inline:The token is readable in
/proc/<pid>/cmdlineand inpsoutput for as long as the session runs.Impact
Any local process running as the same user, and any tool that captures process lists (monitoring, crash reports, shell history of a
pspaste, screenshots), can read a credential that authorizes calls to the T3 Code MCP endpoint. The exposure is local and limited to the same user, but the token ends up in places where people don't expect secrets.Version or commit
0.0.45
Environment
Arch-based Linux,
t3code-binpackage, desktop app, Claude provider.Logs or stack traces
None; observed through process arguments.