Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 10 additions & 6 deletions .claude/skills/triage-issue/SKILL.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -119,24 +119,28 @@ If the issue is complex or the fix is unclear, skip this section and instead not
Use the Python script at `assets/post_linear_comment.py` to handle the entire Linear API interaction. This avoids all shell escaping issues with GraphQL (`$input`, `CommentCreateInput!`) and markdown content (backticks, `$`, quotes).

The script reads `LINEAR_CLIENT_ID` and `LINEAR_CLIENT_SECRET` from environment variables (set from GitHub Actions secrets), obtains an OAuth token, checks for duplicate triage comments, and posts the comment.
1. **Write the report body to a temp file** using the Write tool (not Bash). This keeps markdown completely out of shell.

Write the triage report to `/tmp/triage_report.md`.
1. **Write the report body to a file** using the Write tool (not Bash). This keeps markdown completely out of shell.
- **In CI:** Write to `triage_report.md` in the repository root. The CI sandbox only allows writes inside the working directory; `/tmp` and Bash output redirection are blocked.
- **Locally:** You may use `/tmp/triage_report.md` or `triage_report.md` in the repo root.

2. **Run the script:**

```bash
python3 .claude/skills/triage-issue/assets/post_linear_comment.py "JS-XXXX" "/tmp/triage_report.md"
python3 .claude/skills/triage-issue/assets/post_linear_comment.py "JS-XXXX" "triage_report.md"
```

(Use the same path you wrote to: `triage_report.md` in CI, or `/tmp/triage_report.md` locally if you used that.)

If the script fails (non-zero exit), fall back to printing the full report to the terminal.

Clean up temp files after:
Clean up after:

```bash
rm -f /tmp/triage_report.md
rm -f triage_report.md
```

(In CI only `triage_report.md` in the repo root is writable; use that path for write, script, and rm.)

## Important Rules

**CRITICAL — READ-ONLY POLICY:**
Expand Down
14 changes: 11 additions & 3 deletions .claude/skills/triage-issue/assets/post_linear_comment.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,7 +2,13 @@

TIMEOUT_SECONDS = 30
IDENTIFIER_PATTERN = re.compile(r"^[A-Z]+-\d+$")
ALLOWED_REPORT_DIR = "/tmp/"
# /tmp/ is allowed for local runs; repo cwd is required in CI (sandbox only allows writes in working dir)
ALLOWED_REPORT_PREFIXES = ("/tmp/", os.path.abspath(os.getcwd()) + os.sep)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Path validation fails when script runs from root

Low Severity

When the script runs from the root directory /, the path validation logic creates the prefix // by appending os.sep to /. This causes validation to fail for files in the current directory like /file.md because they don't start with //. While running from / is unlikely in practice, the validation prevents the intended behavior of allowing writes to the current working directory.

Fix in CursorFix in Web



def _report_path_allowed(path: str) -> bool:
abs_path = os.path.abspath(path)
return any(abs_path.startswith(p) for p in ALLOWED_REPORT_PREFIXES)


def graphql(token, query, variables=None):
Expand DownExpand Up@@ -32,8 +38,10 @@ def graphql(token, query, variables=None):
print(f"Invalid identifier format: {identifier}")
sys.exit(1)

if not os.path.abspath(report_path).startswith(ALLOWED_REPORT_DIR):
print(f"Report path must be under {ALLOWED_REPORT_DIR}")
if not _report_path_allowed(report_path):
print(
f"Report path must be under /tmp/ or under current working directory ({os.getcwd()})"
)
sys.exit(1)

client_id = os.environ["LINEAR_CLIENT_ID"]
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/triage-issue.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -68,4 +68,4 @@ jobs:
/triage-issue ${{ steps.parse-issue.outputs.issue_number }} --ci
IMPORTANT: Do NOT wait for approval.
claude_args: |
--max-turns 20 --allowedTools "Write(//tmp/triage_report.md),Bash(gh api *),Bash(gh pr list *),Bash(python3 .claude/skills/triage-issue/assets/post_linear_comment.py *),Bash(rm -f /tmp/triage_report.md)"
--max-turns 20 --allowedTools "Write(triage_report.md),Bash(gh api *),Bash(gh pr list *),Bash(python3 .claude/skills/triage-issue/assets/post_linear_comment.py *),Bash(rm -f triage_report.md)"
Comment thread
cursor[bot] marked this conversation as resolved.
Comment thread
sentry[bot] marked this conversation as resolved.
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 10 additions & 6 deletions .claude/skills/triage-issue/SKILL.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -119,24 +119,28 @@ If the issue is complex or the fix is unclear, skip this section and instead not
Use the Python script at `assets/post_linear_comment.py` to handle the entire Linear API interaction. This avoids all shell escaping issues with GraphQL (`$input`, `CommentCreateInput!`) and markdown content (backticks, `$`, quotes).

The script reads `LINEAR_CLIENT_ID` and `LINEAR_CLIENT_SECRET` from environment variables (set from GitHub Actions secrets), obtains an OAuth token, checks for duplicate triage comments, and posts the comment.
1. **Write the report body to a temp file** using the Write tool (not Bash). This keeps markdown completely out of shell.

Write the triage report to `/tmp/triage_report.md`.
1. **Write the report body to a file** using the Write tool (not Bash). This keeps markdown completely out of shell.
- **In CI:** Write to `triage_report.md` in the repository root. The CI sandbox only allows writes inside the working directory; `/tmp` and Bash output redirection are blocked.
- **Locally:** You may use `/tmp/triage_report.md` or `triage_report.md` in the repo root.

2. **Run the script:**

```bash
python3 .claude/skills/triage-issue/assets/post_linear_comment.py "JS-XXXX" "/tmp/triage_report.md"
python3 .claude/skills/triage-issue/assets/post_linear_comment.py "JS-XXXX" "triage_report.md"
```

(Use the same path you wrote to: `triage_report.md` in CI, or `/tmp/triage_report.md` locally if you used that.)

If the script fails (non-zero exit), fall back to printing the full report to the terminal.

Clean up temp files after:
Clean up after:

```bash
rm -f /tmp/triage_report.md
rm -f triage_report.md
```

(In CI only `triage_report.md` in the repo root is writable; use that path for write, script, and rm.)

## Important Rules

**CRITICAL — READ-ONLY POLICY:**
Expand Down
14 changes: 11 additions & 3 deletions .claude/skills/triage-issue/assets/post_linear_comment.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,7 +2,13 @@

TIMEOUT_SECONDS = 30
IDENTIFIER_PATTERN = re.compile(r"^[A-Z]+-\d+$")
ALLOWED_REPORT_DIR = "/tmp/"
# /tmp/ is allowed for local runs; repo cwd is required in CI (sandbox only allows writes in working dir)
ALLOWED_REPORT_PREFIXES = ("/tmp/", os.path.abspath(os.getcwd()) + os.sep)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Path validation fails when script runs from root

Low Severity

When the script runs from the root directory /, the path validation logic creates the prefix // by appending os.sep to /. This causes validation to fail for files in the current directory like /file.md because they don't start with //. While running from / is unlikely in practice, the validation prevents the intended behavior of allowing writes to the current working directory.

Fix in CursorFix in Web



def _report_path_allowed(path: str) -> bool:
abs_path = os.path.abspath(path)
return any(abs_path.startswith(p) for p in ALLOWED_REPORT_PREFIXES)


def graphql(token, query, variables=None):
Expand DownExpand Up@@ -32,8 +38,10 @@ def graphql(token, query, variables=None):
print(f"Invalid identifier format: {identifier}")
sys.exit(1)

if not os.path.abspath(report_path).startswith(ALLOWED_REPORT_DIR):
print(f"Report path must be under {ALLOWED_REPORT_DIR}")
if not _report_path_allowed(report_path):
print(
f"Report path must be under /tmp/ or under current working directory ({os.getcwd()})"
)
sys.exit(1)

client_id = os.environ["LINEAR_CLIENT_ID"]
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/triage-issue.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -68,4 +68,4 @@ jobs:
/triage-issue ${{ steps.parse-issue.outputs.issue_number }} --ci
IMPORTANT: Do NOT wait for approval.
claude_args: |
--max-turns 20 --allowedTools "Write(//tmp/triage_report.md),Bash(gh api *),Bash(gh pr list *),Bash(python3 .claude/skills/triage-issue/assets/post_linear_comment.py *),Bash(rm -f /tmp/triage_report.md)"
--max-turns 20 --allowedTools "Write(triage_report.md),Bash(gh api *),Bash(gh pr list *),Bash(python3 .claude/skills/triage-issue/assets/post_linear_comment.py *),Bash(rm -f triage_report.md)"
Comment thread
cursor[bot] marked this conversation as resolved.
Comment thread
sentry[bot] marked this conversation as resolved.
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 10 additions & 6 deletions .claude/skills/triage-issue/SKILL.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -119,24 +119,28 @@ If the issue is complex or the fix is unclear, skip this section and instead not
Use the Python script at `assets/post_linear_comment.py` to handle the entire Linear API interaction. This avoids all shell escaping issues with GraphQL (`$input`, `CommentCreateInput!`) and markdown content (backticks, `$`, quotes).

The script reads `LINEAR_CLIENT_ID` and `LINEAR_CLIENT_SECRET` from environment variables (set from GitHub Actions secrets), obtains an OAuth token, checks for duplicate triage comments, and posts the comment.
1. **Write the report body to a temp file** using the Write tool (not Bash). This keeps markdown completely out of shell.

Write the triage report to `/tmp/triage_report.md`.
1. **Write the report body to a file** using the Write tool (not Bash). This keeps markdown completely out of shell.
- **In CI:** Write to `triage_report.md` in the repository root. The CI sandbox only allows writes inside the working directory; `/tmp` and Bash output redirection are blocked.
- **Locally:** You may use `/tmp/triage_report.md` or `triage_report.md` in the repo root.

2. **Run the script:**

```bash
python3 .claude/skills/triage-issue/assets/post_linear_comment.py "JS-XXXX" "/tmp/triage_report.md"
python3 .claude/skills/triage-issue/assets/post_linear_comment.py "JS-XXXX" "triage_report.md"
```

(Use the same path you wrote to: `triage_report.md` in CI, or `/tmp/triage_report.md` locally if you used that.)

If the script fails (non-zero exit), fall back to printing the full report to the terminal.

Clean up temp files after:
Clean up after:

```bash
rm -f /tmp/triage_report.md
rm -f triage_report.md
```

(In CI only `triage_report.md` in the repo root is writable; use that path for write, script, and rm.)

## Important Rules

**CRITICAL — READ-ONLY POLICY:**
Expand Down
14 changes: 11 additions & 3 deletions .claude/skills/triage-issue/assets/post_linear_comment.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,7 +2,13 @@

TIMEOUT_SECONDS = 30
IDENTIFIER_PATTERN = re.compile(r"^[A-Z]+-\d+$")
ALLOWED_REPORT_DIR = "/tmp/"
# /tmp/ is allowed for local runs; repo cwd is required in CI (sandbox only allows writes in working dir)
ALLOWED_REPORT_PREFIXES = ("/tmp/", os.path.abspath(os.getcwd()) + os.sep)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Path validation fails when script runs from root

Low Severity

When the script runs from the root directory /, the path validation logic creates the prefix // by appending os.sep to /. This causes validation to fail for files in the current directory like /file.md because they don't start with //. While running from / is unlikely in practice, the validation prevents the intended behavior of allowing writes to the current working directory.

Fix in CursorFix in Web



def _report_path_allowed(path: str) -> bool:
abs_path = os.path.abspath(path)
return any(abs_path.startswith(p) for p in ALLOWED_REPORT_PREFIXES)


def graphql(token, query, variables=None):
Expand DownExpand Up@@ -32,8 +38,10 @@ def graphql(token, query, variables=None):
print(f"Invalid identifier format: {identifier}")
sys.exit(1)

if not os.path.abspath(report_path).startswith(ALLOWED_REPORT_DIR):
print(f"Report path must be under {ALLOWED_REPORT_DIR}")
if not _report_path_allowed(report_path):
print(
f"Report path must be under /tmp/ or under current working directory ({os.getcwd()})"
)
sys.exit(1)

client_id = os.environ["LINEAR_CLIENT_ID"]
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/triage-issue.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -68,4 +68,4 @@ jobs:
/triage-issue ${{ steps.parse-issue.outputs.issue_number }} --ci
IMPORTANT: Do NOT wait for approval.
claude_args: |
--max-turns 20 --allowedTools "Write(//tmp/triage_report.md),Bash(gh api *),Bash(gh pr list *),Bash(python3 .claude/skills/triage-issue/assets/post_linear_comment.py *),Bash(rm -f /tmp/triage_report.md)"
--max-turns 20 --allowedTools "Write(triage_report.md),Bash(gh api *),Bash(gh pr list *),Bash(python3 .claude/skills/triage-issue/assets/post_linear_comment.py *),Bash(rm -f triage_report.md)"
Comment thread
cursor[bot] marked this conversation as resolved.
Comment thread
sentry[bot] marked this conversation as resolved.
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 10 additions & 6 deletions .claude/skills/triage-issue/SKILL.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -119,24 +119,28 @@ If the issue is complex or the fix is unclear, skip this section and instead not
Use the Python script at `assets/post_linear_comment.py` to handle the entire Linear API interaction. This avoids all shell escaping issues with GraphQL (`$input`, `CommentCreateInput!`) and markdown content (backticks, `$`, quotes).

The script reads `LINEAR_CLIENT_ID` and `LINEAR_CLIENT_SECRET` from environment variables (set from GitHub Actions secrets), obtains an OAuth token, checks for duplicate triage comments, and posts the comment.
1. **Write the report body to a temp file** using the Write tool (not Bash). This keeps markdown completely out of shell.

Write the triage report to `/tmp/triage_report.md`.
1. **Write the report body to a file** using the Write tool (not Bash). This keeps markdown completely out of shell.
- **In CI:** Write to `triage_report.md` in the repository root. The CI sandbox only allows writes inside the working directory; `/tmp` and Bash output redirection are blocked.
- **Locally:** You may use `/tmp/triage_report.md` or `triage_report.md` in the repo root.

2. **Run the script:**

```bash
python3 .claude/skills/triage-issue/assets/post_linear_comment.py "JS-XXXX" "/tmp/triage_report.md"
python3 .claude/skills/triage-issue/assets/post_linear_comment.py "JS-XXXX" "triage_report.md"
```

(Use the same path you wrote to: `triage_report.md` in CI, or `/tmp/triage_report.md` locally if you used that.)

If the script fails (non-zero exit), fall back to printing the full report to the terminal.

Clean up temp files after:
Clean up after:

```bash
rm -f /tmp/triage_report.md
rm -f triage_report.md
```

(In CI only `triage_report.md` in the repo root is writable; use that path for write, script, and rm.)

## Important Rules

**CRITICAL — READ-ONLY POLICY:**
Expand Down
14 changes: 11 additions & 3 deletions .claude/skills/triage-issue/assets/post_linear_comment.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,7 +2,13 @@

TIMEOUT_SECONDS = 30
IDENTIFIER_PATTERN = re.compile(r"^[A-Z]+-\d+$")
ALLOWED_REPORT_DIR = "/tmp/"
# /tmp/ is allowed for local runs; repo cwd is required in CI (sandbox only allows writes in working dir)
ALLOWED_REPORT_PREFIXES = ("/tmp/", os.path.abspath(os.getcwd()) + os.sep)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Path validation fails when script runs from root

Low Severity

When the script runs from the root directory /, the path validation logic creates the prefix // by appending os.sep to /. This causes validation to fail for files in the current directory like /file.md because they don't start with //. While running from / is unlikely in practice, the validation prevents the intended behavior of allowing writes to the current working directory.

Fix in CursorFix in Web



def _report_path_allowed(path: str) -> bool:
abs_path = os.path.abspath(path)
return any(abs_path.startswith(p) for p in ALLOWED_REPORT_PREFIXES)


def graphql(token, query, variables=None):
Expand DownExpand Up@@ -32,8 +38,10 @@ def graphql(token, query, variables=None):
print(f"Invalid identifier format: {identifier}")
sys.exit(1)

if not os.path.abspath(report_path).startswith(ALLOWED_REPORT_DIR):
print(f"Report path must be under {ALLOWED_REPORT_DIR}")
if not _report_path_allowed(report_path):
print(
f"Report path must be under /tmp/ or under current working directory ({os.getcwd()})"
)
sys.exit(1)

client_id = os.environ["LINEAR_CLIENT_ID"]
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/triage-issue.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -68,4 +68,4 @@ jobs:
/triage-issue ${{ steps.parse-issue.outputs.issue_number }} --ci
IMPORTANT: Do NOT wait for approval.
claude_args: |
--max-turns 20 --allowedTools "Write(//tmp/triage_report.md),Bash(gh api *),Bash(gh pr list *),Bash(python3 .claude/skills/triage-issue/assets/post_linear_comment.py *),Bash(rm -f /tmp/triage_report.md)"
--max-turns 20 --allowedTools "Write(triage_report.md),Bash(gh api *),Bash(gh pr list *),Bash(python3 .claude/skills/triage-issue/assets/post_linear_comment.py *),Bash(rm -f triage_report.md)"
Comment thread
cursor[bot] marked this conversation as resolved.
Comment thread
sentry[bot] marked this conversation as resolved.
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 10 additions & 6 deletions .claude/skills/triage-issue/SKILL.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -119,24 +119,28 @@ If the issue is complex or the fix is unclear, skip this section and instead not
Use the Python script at `assets/post_linear_comment.py` to handle the entire Linear API interaction. This avoids all shell escaping issues with GraphQL (`$input`, `CommentCreateInput!`) and markdown content (backticks, `$`, quotes).

The script reads `LINEAR_CLIENT_ID` and `LINEAR_CLIENT_SECRET` from environment variables (set from GitHub Actions secrets), obtains an OAuth token, checks for duplicate triage comments, and posts the comment.
1. **Write the report body to a temp file** using the Write tool (not Bash). This keeps markdown completely out of shell.

Write the triage report to `/tmp/triage_report.md`.
1. **Write the report body to a file** using the Write tool (not Bash). This keeps markdown completely out of shell.
- **In CI:** Write to `triage_report.md` in the repository root. The CI sandbox only allows writes inside the working directory; `/tmp` and Bash output redirection are blocked.
- **Locally:** You may use `/tmp/triage_report.md` or `triage_report.md` in the repo root.

2. **Run the script:**

```bash
python3 .claude/skills/triage-issue/assets/post_linear_comment.py "JS-XXXX" "/tmp/triage_report.md"
python3 .claude/skills/triage-issue/assets/post_linear_comment.py "JS-XXXX" "triage_report.md"
```

(Use the same path you wrote to: `triage_report.md` in CI, or `/tmp/triage_report.md` locally if you used that.)

If the script fails (non-zero exit), fall back to printing the full report to the terminal.

Clean up temp files after:
Clean up after:

```bash
rm -f /tmp/triage_report.md
rm -f triage_report.md
```

(In CI only `triage_report.md` in the repo root is writable; use that path for write, script, and rm.)

## Important Rules

**CRITICAL — READ-ONLY POLICY:**
Expand Down
14 changes: 11 additions & 3 deletions .claude/skills/triage-issue/assets/post_linear_comment.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,7 +2,13 @@

TIMEOUT_SECONDS = 30
IDENTIFIER_PATTERN = re.compile(r"^[A-Z]+-\d+$")
ALLOWED_REPORT_DIR = "/tmp/"
# /tmp/ is allowed for local runs; repo cwd is required in CI (sandbox only allows writes in working dir)
ALLOWED_REPORT_PREFIXES = ("/tmp/", os.path.abspath(os.getcwd()) + os.sep)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Path validation fails when script runs from root

Low Severity

When the script runs from the root directory /, the path validation logic creates the prefix // by appending os.sep to /. This causes validation to fail for files in the current directory like /file.md because they don't start with //. While running from / is unlikely in practice, the validation prevents the intended behavior of allowing writes to the current working directory.

Fix in CursorFix in Web



def _report_path_allowed(path: str) -> bool:
abs_path = os.path.abspath(path)
return any(abs_path.startswith(p) for p in ALLOWED_REPORT_PREFIXES)


def graphql(token, query, variables=None):
Expand DownExpand Up@@ -32,8 +38,10 @@ def graphql(token, query, variables=None):
print(f"Invalid identifier format: {identifier}")
sys.exit(1)

if not os.path.abspath(report_path).startswith(ALLOWED_REPORT_DIR):
print(f"Report path must be under {ALLOWED_REPORT_DIR}")
if not _report_path_allowed(report_path):
print(
f"Report path must be under /tmp/ or under current working directory ({os.getcwd()})"
)
sys.exit(1)

client_id = os.environ["LINEAR_CLIENT_ID"]
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/triage-issue.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -68,4 +68,4 @@ jobs:
/triage-issue ${{ steps.parse-issue.outputs.issue_number }} --ci
IMPORTANT: Do NOT wait for approval.
claude_args: |
--max-turns 20 --allowedTools "Write(//tmp/triage_report.md),Bash(gh api *),Bash(gh pr list *),Bash(python3 .claude/skills/triage-issue/assets/post_linear_comment.py *),Bash(rm -f /tmp/triage_report.md)"
--max-turns 20 --allowedTools "Write(triage_report.md),Bash(gh api *),Bash(gh pr list *),Bash(python3 .claude/skills/triage-issue/assets/post_linear_comment.py *),Bash(rm -f triage_report.md)"
Comment thread
cursor[bot] marked this conversation as resolved.
Comment thread
sentry[bot] marked this conversation as resolved.
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 10 additions & 6 deletions .claude/skills/triage-issue/SKILL.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -119,24 +119,28 @@ If the issue is complex or the fix is unclear, skip this section and instead not
Use the Python script at `assets/post_linear_comment.py` to handle the entire Linear API interaction. This avoids all shell escaping issues with GraphQL (`$input`, `CommentCreateInput!`) and markdown content (backticks, `$`, quotes).

The script reads `LINEAR_CLIENT_ID` and `LINEAR_CLIENT_SECRET` from environment variables (set from GitHub Actions secrets), obtains an OAuth token, checks for duplicate triage comments, and posts the comment.
1. **Write the report body to a temp file** using the Write tool (not Bash). This keeps markdown completely out of shell.

Write the triage report to `/tmp/triage_report.md`.
1. **Write the report body to a file** using the Write tool (not Bash). This keeps markdown completely out of shell.
- **In CI:** Write to `triage_report.md` in the repository root. The CI sandbox only allows writes inside the working directory; `/tmp` and Bash output redirection are blocked.
- **Locally:** You may use `/tmp/triage_report.md` or `triage_report.md` in the repo root.

2. **Run the script:**

```bash
python3 .claude/skills/triage-issue/assets/post_linear_comment.py "JS-XXXX" "/tmp/triage_report.md"
python3 .claude/skills/triage-issue/assets/post_linear_comment.py "JS-XXXX" "triage_report.md"
```

(Use the same path you wrote to: `triage_report.md` in CI, or `/tmp/triage_report.md` locally if you used that.)

If the script fails (non-zero exit), fall back to printing the full report to the terminal.

Clean up temp files after:
Clean up after:

```bash
rm -f /tmp/triage_report.md
rm -f triage_report.md
```

(In CI only `triage_report.md` in the repo root is writable; use that path for write, script, and rm.)

## Important Rules

**CRITICAL — READ-ONLY POLICY:**
Expand Down
14 changes: 11 additions & 3 deletions .claude/skills/triage-issue/assets/post_linear_comment.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,7 +2,13 @@

TIMEOUT_SECONDS = 30
IDENTIFIER_PATTERN = re.compile(r"^[A-Z]+-\d+$")
ALLOWED_REPORT_DIR = "/tmp/"
# /tmp/ is allowed for local runs; repo cwd is required in CI (sandbox only allows writes in working dir)
ALLOWED_REPORT_PREFIXES = ("/tmp/", os.path.abspath(os.getcwd()) + os.sep)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Path validation fails when script runs from root

Low Severity

When the script runs from the root directory /, the path validation logic creates the prefix // by appending os.sep to /. This causes validation to fail for files in the current directory like /file.md because they don't start with //. While running from / is unlikely in practice, the validation prevents the intended behavior of allowing writes to the current working directory.

Fix in CursorFix in Web



def _report_path_allowed(path: str) -> bool:
abs_path = os.path.abspath(path)
return any(abs_path.startswith(p) for p in ALLOWED_REPORT_PREFIXES)


def graphql(token, query, variables=None):
Expand DownExpand Up@@ -32,8 +38,10 @@ def graphql(token, query, variables=None):
print(f"Invalid identifier format: {identifier}")
sys.exit(1)

if not os.path.abspath(report_path).startswith(ALLOWED_REPORT_DIR):
print(f"Report path must be under {ALLOWED_REPORT_DIR}")
if not _report_path_allowed(report_path):
print(
f"Report path must be under /tmp/ or under current working directory ({os.getcwd()})"
)
sys.exit(1)

client_id = os.environ["LINEAR_CLIENT_ID"]
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/triage-issue.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -68,4 +68,4 @@ jobs:
/triage-issue ${{ steps.parse-issue.outputs.issue_number }} --ci
IMPORTANT: Do NOT wait for approval.
claude_args: |
--max-turns 20 --allowedTools "Write(//tmp/triage_report.md),Bash(gh api *),Bash(gh pr list *),Bash(python3 .claude/skills/triage-issue/assets/post_linear_comment.py *),Bash(rm -f /tmp/triage_report.md)"
--max-turns 20 --allowedTools "Write(triage_report.md),Bash(gh api *),Bash(gh pr list *),Bash(python3 .claude/skills/triage-issue/assets/post_linear_comment.py *),Bash(rm -f triage_report.md)"
Comment thread
cursor[bot] marked this conversation as resolved.
Comment thread
sentry[bot] marked this conversation as resolved.
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 10 additions & 6 deletions .claude/skills/triage-issue/SKILL.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -119,24 +119,28 @@ If the issue is complex or the fix is unclear, skip this section and instead not
Use the Python script at `assets/post_linear_comment.py` to handle the entire Linear API interaction. This avoids all shell escaping issues with GraphQL (`$input`, `CommentCreateInput!`) and markdown content (backticks, `$`, quotes).

The script reads `LINEAR_CLIENT_ID` and `LINEAR_CLIENT_SECRET` from environment variables (set from GitHub Actions secrets), obtains an OAuth token, checks for duplicate triage comments, and posts the comment.
1. **Write the report body to a temp file** using the Write tool (not Bash). This keeps markdown completely out of shell.

Write the triage report to `/tmp/triage_report.md`.
1. **Write the report body to a file** using the Write tool (not Bash). This keeps markdown completely out of shell.
- **In CI:** Write to `triage_report.md` in the repository root. The CI sandbox only allows writes inside the working directory; `/tmp` and Bash output redirection are blocked.
- **Locally:** You may use `/tmp/triage_report.md` or `triage_report.md` in the repo root.

2. **Run the script:**

```bash
python3 .claude/skills/triage-issue/assets/post_linear_comment.py "JS-XXXX" "/tmp/triage_report.md"
python3 .claude/skills/triage-issue/assets/post_linear_comment.py "JS-XXXX" "triage_report.md"
```

(Use the same path you wrote to: `triage_report.md` in CI, or `/tmp/triage_report.md` locally if you used that.)

If the script fails (non-zero exit), fall back to printing the full report to the terminal.

Clean up temp files after:
Clean up after:

```bash
rm -f /tmp/triage_report.md
rm -f triage_report.md
```

(In CI only `triage_report.md` in the repo root is writable; use that path for write, script, and rm.)

## Important Rules

**CRITICAL — READ-ONLY POLICY:**
Expand Down
14 changes: 11 additions & 3 deletions .claude/skills/triage-issue/assets/post_linear_comment.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,7 +2,13 @@

TIMEOUT_SECONDS = 30
IDENTIFIER_PATTERN = re.compile(r"^[A-Z]+-\d+$")
ALLOWED_REPORT_DIR = "/tmp/"
# /tmp/ is allowed for local runs; repo cwd is required in CI (sandbox only allows writes in working dir)
ALLOWED_REPORT_PREFIXES = ("/tmp/", os.path.abspath(os.getcwd()) + os.sep)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Path validation fails when script runs from root

Low Severity

When the script runs from the root directory /, the path validation logic creates the prefix // by appending os.sep to /. This causes validation to fail for files in the current directory like /file.md because they don't start with //. While running from / is unlikely in practice, the validation prevents the intended behavior of allowing writes to the current working directory.

Fix in CursorFix in Web



def _report_path_allowed(path: str) -> bool:
abs_path = os.path.abspath(path)
return any(abs_path.startswith(p) for p in ALLOWED_REPORT_PREFIXES)


def graphql(token, query, variables=None):
Expand DownExpand Up@@ -32,8 +38,10 @@ def graphql(token, query, variables=None):
print(f"Invalid identifier format: {identifier}")
sys.exit(1)

if not os.path.abspath(report_path).startswith(ALLOWED_REPORT_DIR):
print(f"Report path must be under {ALLOWED_REPORT_DIR}")
if not _report_path_allowed(report_path):
print(
f"Report path must be under /tmp/ or under current working directory ({os.getcwd()})"
)
sys.exit(1)

client_id = os.environ["LINEAR_CLIENT_ID"]
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/triage-issue.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -68,4 +68,4 @@ jobs:
/triage-issue ${{ steps.parse-issue.outputs.issue_number }} --ci
IMPORTANT: Do NOT wait for approval.
claude_args: |
--max-turns 20 --allowedTools "Write(//tmp/triage_report.md),Bash(gh api *),Bash(gh pr list *),Bash(python3 .claude/skills/triage-issue/assets/post_linear_comment.py *),Bash(rm -f /tmp/triage_report.md)"
--max-turns 20 --allowedTools "Write(triage_report.md),Bash(gh api *),Bash(gh pr list *),Bash(python3 .claude/skills/triage-issue/assets/post_linear_comment.py *),Bash(rm -f triage_report.md)"
Comment thread
cursor[bot] marked this conversation as resolved.
Comment thread
sentry[bot] marked this conversation as resolved.
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 10 additions & 6 deletions .claude/skills/triage-issue/SKILL.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -119,24 +119,28 @@ If the issue is complex or the fix is unclear, skip this section and instead not
Use the Python script at `assets/post_linear_comment.py` to handle the entire Linear API interaction. This avoids all shell escaping issues with GraphQL (`$input`, `CommentCreateInput!`) and markdown content (backticks, `$`, quotes).

The script reads `LINEAR_CLIENT_ID` and `LINEAR_CLIENT_SECRET` from environment variables (set from GitHub Actions secrets), obtains an OAuth token, checks for duplicate triage comments, and posts the comment.
1. **Write the report body to a temp file** using the Write tool (not Bash). This keeps markdown completely out of shell.

Write the triage report to `/tmp/triage_report.md`.
1. **Write the report body to a file** using the Write tool (not Bash). This keeps markdown completely out of shell.
- **In CI:** Write to `triage_report.md` in the repository root. The CI sandbox only allows writes inside the working directory; `/tmp` and Bash output redirection are blocked.
- **Locally:** You may use `/tmp/triage_report.md` or `triage_report.md` in the repo root.

2. **Run the script:**

```bash
python3 .claude/skills/triage-issue/assets/post_linear_comment.py "JS-XXXX" "/tmp/triage_report.md"
python3 .claude/skills/triage-issue/assets/post_linear_comment.py "JS-XXXX" "triage_report.md"
```

(Use the same path you wrote to: `triage_report.md` in CI, or `/tmp/triage_report.md` locally if you used that.)

If the script fails (non-zero exit), fall back to printing the full report to the terminal.

Clean up temp files after:
Clean up after:

```bash
rm -f /tmp/triage_report.md
rm -f triage_report.md
```

(In CI only `triage_report.md` in the repo root is writable; use that path for write, script, and rm.)

## Important Rules

**CRITICAL — READ-ONLY POLICY:**
Expand Down
14 changes: 11 additions & 3 deletions .claude/skills/triage-issue/assets/post_linear_comment.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,7 +2,13 @@

TIMEOUT_SECONDS = 30
IDENTIFIER_PATTERN = re.compile(r"^[A-Z]+-\d+$")
ALLOWED_REPORT_DIR = "/tmp/"
# /tmp/ is allowed for local runs; repo cwd is required in CI (sandbox only allows writes in working dir)
ALLOWED_REPORT_PREFIXES = ("/tmp/", os.path.abspath(os.getcwd()) + os.sep)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Path validation fails when script runs from root

Low Severity

When the script runs from the root directory /, the path validation logic creates the prefix // by appending os.sep to /. This causes validation to fail for files in the current directory like /file.md because they don't start with //. While running from / is unlikely in practice, the validation prevents the intended behavior of allowing writes to the current working directory.

Fix in CursorFix in Web



def _report_path_allowed(path: str) -> bool:
abs_path = os.path.abspath(path)
return any(abs_path.startswith(p) for p in ALLOWED_REPORT_PREFIXES)


def graphql(token, query, variables=None):
Expand DownExpand Up@@ -32,8 +38,10 @@ def graphql(token, query, variables=None):
print(f"Invalid identifier format: {identifier}")
sys.exit(1)

if not os.path.abspath(report_path).startswith(ALLOWED_REPORT_DIR):
print(f"Report path must be under {ALLOWED_REPORT_DIR}")
if not _report_path_allowed(report_path):
print(
f"Report path must be under /tmp/ or under current working directory ({os.getcwd()})"
)
sys.exit(1)

client_id = os.environ["LINEAR_CLIENT_ID"]
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/triage-issue.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -68,4 +68,4 @@ jobs:
/triage-issue ${{ steps.parse-issue.outputs.issue_number }} --ci
IMPORTANT: Do NOT wait for approval.
claude_args: |
--max-turns 20 --allowedTools "Write(//tmp/triage_report.md),Bash(gh api *),Bash(gh pr list *),Bash(python3 .claude/skills/triage-issue/assets/post_linear_comment.py *),Bash(rm -f /tmp/triage_report.md)"
--max-turns 20 --allowedTools "Write(triage_report.md),Bash(gh api *),Bash(gh pr list *),Bash(python3 .claude/skills/triage-issue/assets/post_linear_comment.py *),Bash(rm -f triage_report.md)"
Comment thread
cursor[bot] marked this conversation as resolved.
Comment thread
sentry[bot] marked this conversation as resolved.
Loading