Repository navigation
Remove broad shell pre-approval from CLI setup - #60
Merged
georgeatparallel merged 12 commits intoOct 5, 2026
Merged
georgeatparallel merged 12 commits into
georgeatparallel merged 12 commits into
Conversation
supriya-parallel
marked this pull request as ready for review
October 2, 2026 19:49
sergei1152
reviewed
Oct 2, 2026
sergei1152
reviewed
Oct 2, 2026
| description: Set up and maintain the Parallel CLI (install, auth, balance, skills install) | ||
| description: Install or upgrade the Parallel CLI and install its skills without reading, requesting, or handling credentials. Authentication stays in the user's trusted terminal. | ||
| user-invocable: true | ||
| allowed-tools: Bash(command:*), Bash(brew:*), Bash(uv:*), Bash(npm:*), Bash(pipx:*), Bash(curl:*), Bash(rm:*), Bash(parallel-cli:*) |
Collaborator
There was a problem hiding this comment.
Claude’s directory flags this because it pre-approves any command under curl, npm, uv, etc. Removing it keeps the commands available, but they follow the user’s normal approval settings
Also - removed all the other changes to keep this minimal
sergei1152
requested changes
Oct 2, 2026
sergei1152
left a comment
Contributor
There was a problem hiding this comment.
this may break agentic onboarding. plz test the parallel-cli-setup skill with multiple agents or keep as is
sergei1152
reviewed
Oct 2, 2026
sergei1152
reviewed
Oct 2, 2026
georgeatparallel
approved these changes
Oct 5, 2026
sergei1152
approved these changes
Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The Claude directory flags the setup skill's
allowed-toolsentry because it pre-approves broad package-manager and shell commands. Remove that entry so setup uses the client's normal command approvals.This is a one-line change. CLI authentication, onboarding, migration examples, and credential diagnostics retain their existing behavior. The expanded directory findings explicitly allow credentials for the destination's own vendor to remain for reviewer confirmation, so removing working authentication flows is unnecessary for submission. The synthetic provider-scanner fixtures also stay readable.
Validation: 37 Python tests pass; plugin and marketplace validation pass (the existing root
CLAUDE.mdwarning remains);git diff --checkpasses. Portal validation of3cc97c4passes and removes the broad-shell hold. Eight credential findings and two name/publisher findings remain for review. Metadata is handled separately in #61.Claude's validation result definitions distinguish submission blockers from reviewer holds. After merging, revalidate the official repository's
mainbefore submitting.