You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Use WebFetch to download only the files needed for the user's selections from the GitHub URLs above. Extract the raw file content from each response.
WebFetch converts the page to markdown and answers a prompt against it using a small fast model. It's a summarizing reader, not a downloader — there is no guarantee the bytes come back intact. The two files where that matters most are two of the ones it's asked to install:
scripts/statusline.sh — ANSI escape sequences, nested quoting, and a jq program using // and @tsv
Silently corrupting a user's settings.json is about the worst failure mode an installer has available, and README.md:15 makes /trailofbits:config the primary install path for first-time setup.
Suggested fix
Use Bash: curl -fsSL <raw-url> -o <dest>. Or skip the network entirely — the README has already had the user clone the repo, so cp from the working tree. Reserve WebFetch for reading pages, never for transferring files.
Three smaller defects in the same file
Step 5 self-installs this command file, but it isn't in the fetch list, so no source is defined for its own content — and the path it gets fetched from doesn't exist. This is the root cause of config.md used during install is missing in the repo #49: the install tries commands/trailofbits/config.md and 404s, because the file actually lives at .claude/commands/trailofbits/config.md. Either move the file or fix the path, and add it to the fetch list.
The fetch list and the component menu both omit commands/merge-dependabot.md, which the repo ships and README.md:548 tells you to install.
The menu offers "MCP servers — Context7, Exa, Granola". Granola isn't in mcp-template.json, so it's an option that can't be fulfilled.
Note that the MCP install step has a separate problem, filed separately: the location it writes to isn't a user-scope MCP config at all.
Found while reviewing the repo against Anthropic's current docs and the installed CLI (2.1.238).
.claude/commands/trailofbits/config.md:5instructs:and
:37:WebFetch converts the page to markdown and answers a prompt against it using a small fast model. It's a summarizing reader, not a downloader — there is no guarantee the bytes come back intact. The two files where that matters most are two of the ones it's asked to install:
scripts/statusline.sh— ANSI escape sequences, nested quoting, and ajqprogram using//and@tsvsettings.json— hook commands containing escaped\"inside a shell pipeline inside JSONSilently corrupting a user's
settings.jsonis about the worst failure mode an installer has available, andREADME.md:15makes/trailofbits:configthe primary install path for first-time setup.Suggested fix
Use Bash:
curl -fsSL <raw-url> -o <dest>. Or skip the network entirely — the README has already had the user clone the repo, socpfrom the working tree. Reserve WebFetch for reading pages, never for transferring files.Three smaller defects in the same file
commands/trailofbits/config.mdand 404s, because the file actually lives at.claude/commands/trailofbits/config.md. Either move the file or fix the path, and add it to the fetch list.commands/merge-dependabot.md, which the repo ships andREADME.md:548tells you to install.mcp-template.json, so it's an option that can't be fulfilled.Note that the MCP install step has a separate problem, filed separately: the location it writes to isn't a user-scope MCP config at all.
Found while reviewing the repo against Anthropic's current docs and the installed CLI (2.1.238).