Harden GH_AW_MCP_CLI_SERVERS shell export to resolve code scanning alert #580#31238
Merged
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot
AI
changed the title
[WIP] Fix code scanning alert 580
Harden GH_AW_MCP_CLI_SERVERS shell export to resolve code scanning alert #580
May 9, 2026
Contributor
There was a problem hiding this comment.
Pull request overview
Hardens the generated workflow script output to prevent shell-quoting injection when exporting GH_AW_MCP_CLI_SERVERS (fixing code scanning alert #580).
Changes:
- Shell-escapes the marshaled JSON for
GH_AW_MCP_CLI_SERVERSusingshellEscapeArg(...). - Uses the escaped JSON consistently for both
export GH_AW_MCP_CLI_SERVERS=...and writing to$GITHUB_ENV.
Show a summary per file
| File | Description |
|---|---|
pkg/workflow/mcp_setup_generator.go |
Applies shellEscapeArg to the JSON payload before emitting it into shell export and $GITHUB_ENV append lines. |
Copilot's findings
Tip
Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
- Files reviewed: 1/1 changed files
- Comments generated: 0
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bug Fix
Alert #580 flagged unsafe shell quoting when emitting
GH_AW_MCP_CLI_SERVERSin generated workflow script content. This change applies proper shell argument escaping at the sink so JSON payloads containing quotes cannot break command structure.What was the bug?
Direct interpolation wrote JSON into shell commands with ad hoc quoting, allowing embedded
'to terminate quotes and corrupt the export/$GITHUB_ENVwrite path.How did you fix it?
Applied
shellEscapeArg(...)to the marshaled JSON before writing both command lines inwriteMCPGatewayExports(pkg/workflow/mcp_setup_generator.go), and used the escaped value consistently for:export GH_AW_MCP_CLI_SERVERS=...echo GH_AW_MCP_CLI_SERVERS=... >> "$GITHUB_ENV"Example (before/after)