Skip to content

skills: remoteHeadSha() can open a Git Credential Manager dialog on Windows (GIT_TERMINAL_PROMPT does not cover GUI helpers; slug unvalidated) #4702

Description

@jmax91505-ctrl

Summary

packages/cli/src/utils/skillsManifest.ts remoteHeadSha() runs

execFileAsync("git", ["ls-remote", `https://github.com/${repoSlug}.git`, "refs/heads/main"], { env: { ...process.env, GIT_TERMINAL_PROMPT: "0" } })

GIT_TERMINAL_PROMPT=0 only suppresses terminal prompts. On Windows with Git Credential Manager (the Git for Windows default), a slug for a nonexistent or private repository makes GitHub answer with an authentication challenge, and GCM opens a GUI "Connect to GitHub" window instead of failing. The function's catch never sees it because the process is blocked on the dialog until the user cancels. repoSlug is also passed through unvalidated, so any --source value shaped like a/b reaches git.

We hit the same mechanism this week through a different caller (OpenCode's plugin install, reported at anomalyco/opencode#51943) and noticed this helper has the same latent shape while tracing it.

Suggested fix

  • Validate the slug before spawning: /^[\w.-]+\/[\w.-]+$/, else return null.
  • Spawn git so it can never prompt: git -c credential.helper= ls-remote ... plus GCM_INTERACTIVE: "never" and GIT_ASKPASS: "" in the env. An anonymous read of a public repo never needs a credential helper, so disabling it for this call loses nothing.

Low priority; reported for completeness while the details were fresh.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions