Skip to content

/trailofbits:config installs files with WebFetch, which cannot transfer them intact #56

Description

@e-q

.claude/commands/trailofbits/config.md:5 instructs:

Fetch each file from GitHub using WebFetch.

and :37:

Use WebFetch to download only the files needed for the user's selections from the GitHub URLs above. Extract the raw file content from each response.

WebFetch converts the page to markdown and answers a prompt against it using a small fast model. It's a summarizing reader, not a downloader — there is no guarantee the bytes come back intact. The two files where that matters most are two of the ones it's asked to install:

  • scripts/statusline.sh — ANSI escape sequences, nested quoting, and a jq program using // and @tsv
  • settings.json — hook commands containing escaped \" inside a shell pipeline inside JSON

Silently corrupting a user's settings.json is about the worst failure mode an installer has available, and README.md:15 makes /trailofbits:config the primary install path for first-time setup.

Suggested fix

Use Bash: curl -fsSL <raw-url> -o <dest>. Or skip the network entirely — the README has already had the user clone the repo, so cp from the working tree. Reserve WebFetch for reading pages, never for transferring files.

Three smaller defects in the same file

  • Step 5 self-installs this command file, but it isn't in the fetch list, so no source is defined for its own content — and the path it gets fetched from doesn't exist. This is the root cause of config.md used during install is missing in the repo #49: the install tries commands/trailofbits/config.md and 404s, because the file actually lives at .claude/commands/trailofbits/config.md. Either move the file or fix the path, and add it to the fetch list.
  • The fetch list and the component menu both omit commands/merge-dependabot.md, which the repo ships and README.md:548 tells you to install.
  • The menu offers "MCP servers — Context7, Exa, Granola". Granola isn't in mcp-template.json, so it's an option that can't be fulfilled.

Note that the MCP install step has a separate problem, filed separately: the location it writes to isn't a user-scope MCP config at all.


Found while reviewing the repo against Anthropic's current docs and the installed CLI (2.1.238).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions