Skip to content

Remove broad shell pre-approval from CLI setup - #60

Merged
georgeatparallel merged 12 commits into
parallel-web:mainfrom
supriya-parallel:codex/remove-skill-credential-reads
Oct 5, 2026
Merged

georgeatparallel merged 12 commits into
parallel-web:mainfrom
supriya-parallel:codex/remove-skill-credential-reads

Conversation

@supriya-parallel

@supriya-parallel supriya-parallel commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

The Claude directory flags the setup skill's allowed-tools entry because it pre-approves broad package-manager and shell commands. Remove that entry so setup uses the client's normal command approvals.

This is a one-line change. CLI authentication, onboarding, migration examples, and credential diagnostics retain their existing behavior. The expanded directory findings explicitly allow credentials for the destination's own vendor to remain for reviewer confirmation, so removing working authentication flows is unnecessary for submission. The synthetic provider-scanner fixtures also stay readable.

Validation: 37 Python tests pass; plugin and marketplace validation pass (the existing root CLAUDE.md warning remains); git diff --check passes. Portal validation of 3cc97c4 passes and removes the broad-shell hold. Eight credential findings and two name/publisher findings remain for review. Metadata is handled separately in #61.

Claude's validation result definitions distinguish submission blockers from reviewer holds. After merging, revalidate the official repository's main before submitting.

@supriya-parallel supriya-parallel changed the title Keep the OpenAI submission credential-free Keep Claude plugin skills out of credential stores Sep 29, 2026
@supriya-parallel supriya-parallel changed the title Keep Claude plugin skills out of credential stores Resolve Claude credential and shell policy holds Oct 2, 2026
@supriya-parallel
supriya-parallel marked this pull request as ready for review October 2, 2026 19:49
@supriya-parallel
supriya-parallel requested a review from a team October 2, 2026 19:49
Comment thread skills/parallel-cli-setup/SKILL.md Outdated
description: Set up and maintain the Parallel CLI (install, auth, balance, skills install)
description: Install or upgrade the Parallel CLI and install its skills without reading, requesting, or handling credentials. Authentication stays in the user's trusted terminal.
user-invocable: true
allowed-tools: Bash(command:*), Bash(brew:*), Bash(uv:*), Bash(npm:*), Bash(pipx:*), Bash(curl:*), Bash(rm:*), Bash(parallel-cli:*)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

why remove this?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude’s directory flags this because it pre-approves any command under curl, npm, uv, etc. Removing it keeps the commands available, but they follow the user’s normal approval settings

Also - removed all the other changes to keep this minimal

@sergei1152 sergei1152 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this may break agentic onboarding. plz test the parallel-cli-setup skill with multiple agents or keep as is

Comment thread skills/parallel-cli-setup/SKILL.md
Comment thread skills/parallel-deep-research/SKILL.md Outdated
@georgeatparallel georgeatparallel changed the title Resolve Claude credential and shell policy holds Remove broad shell pre-approval from CLI setup Oct 5, 2026
@georgeatparallel
georgeatparallel merged commit 41c7730 into parallel-web:main Oct 5, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants