Skip to content
Closed
172 changes: 172 additions & 0 deletions .auto-claude-security.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,172 @@
{
"base_commands": [
".",
"[",
"[[",
"ag",
"awk",
"basename",
"bash",
"bc",
"break",
"cat",
"cd",
"chmod",
"clear",
"cmp",
"column",
"comm",
"command",
"continue",
"cp",
"curl",
"cut",
"date",
"df",
"diff",
"dig",
"dirname",
"du",
"echo",
"egrep",
"env",
"eval",
"exec",
"exit",
"expand",
"export",
"expr",
"false",
"fd",
"fgrep",
"file",
"find",
"fmt",
"fold",
"gawk",
"gh",
"git",
"grep",
"gunzip",
"gzip",
"head",
"help",
"host",
"iconv",
"id",
"jobs",
"join",
"jq",
"kill",
"killall",
"less",
"let",
"ln",
"ls",
"lsof",
"man",
"mkdir",
"mktemp",
"more",
"mv",
"nl",
"paste",
"pgrep",
"ping",
"pkill",
"popd",
"printenv",
"printf",
"ps",
"pushd",
"pwd",
"read",
"readlink",
"realpath",
"reset",
"return",
"rev",
"rg",
"rm",
"rmdir",
"sed",
"seq",
"set",
"sh",
"shuf",
"sleep",
"sort",
"source",
"split",
"stat",
"tail",
"tar",
"tee",
"test",
"time",
"timeout",
"touch",
"tr",
"tree",
"true",
"type",
"uname",
"unexpand",
"uniq",
"unset",
"unzip",
"watch",
"wc",
"wget",
"whereis",
"which",
"whoami",
"xargs",
"yes",
"yq",
"zip",
"zsh"
],
"stack_commands": [
"node",
"npm",
"npx",
"pnpm",
"pnpx"
],
"script_commands": [
"bun",
"npm",
"pnpm",
"yarn"
],
"custom_commands": [],
"detected_stack": {
"languages": [
"javascript"
],
"package_managers": [
"pnpm"
],
"frameworks": [],
"databases": [],
"infrastructure": [],
"cloud_providers": [],
"code_quality_tools": [],
"version_managers": []
},
"custom_scripts": {
"npm_scripts": [
"start",
"dev"
],
"make_targets": [],
"poetry_scripts": [],
"cargo_aliases": [],
"shell_scripts": []
},
"project_dir": "/Users/billchirico/Developer/bill-bot",
"created_at": "2026-02-03T19:51:09.135836",
"project_hash": "51a4f617fc8ece9b63e20f8a9950e73b",
"inherited_from": "/Users/billchirico/Developer/bill-bot"
}
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Development files with local paths accidentally committed

Medium Severity

Several development tool configuration files containing local file paths (/Users/billchirico/Developer/bill-bot) and session state have been committed to the repository. These files (.auto-claude-security.json, .auto-claude-status, .claude_settings.json) appear to be auto-generated development tooling artifacts. While .auto-claude/ is in .gitignore, these root-level files are not excluded and expose developer-specific machine paths and workflow state that shouldn't be in version control.

Additional Locations (2)

Fix in Cursor Fix in Web

25 changes: 25 additions & 0 deletions .auto-claude-status
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
{
"active": true,
"spec": "010-user-specific-conversation-history",
"state": "building",
"subtasks": {
"completed": 5,
"total": 6,
"in_progress": 1,
"failed": 0
},
"phase": {
"current": "Manual Testing & Verification",
"id": null,
"total": 2
},
"workers": {
"active": 0,
"max": 1
},
"session": {
"number": 7,
"started_at": "2026-02-03T20:34:14.067043"
},
"last_update": "2026-02-03T20:46:53.877446"
}
39 changes: 39 additions & 0 deletions .claude_settings.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
{
"sandbox": {
"enabled": true,
"autoAllowBashIfSandboxed": true
},
"permissions": {
"defaultMode": "acceptEdits",
"allow": [
"Read(./**)",
"Write(./**)",
"Edit(./**)",
"Glob(./**)",
"Grep(./**)",
"Read(/Users/billchirico/Developer/bill-bot/.auto-claude/worktrees/tasks/010-user-specific-conversation-history/**)",
"Write(/Users/billchirico/Developer/bill-bot/.auto-claude/worktrees/tasks/010-user-specific-conversation-history/**)",
"Edit(/Users/billchirico/Developer/bill-bot/.auto-claude/worktrees/tasks/010-user-specific-conversation-history/**)",
"Glob(/Users/billchirico/Developer/bill-bot/.auto-claude/worktrees/tasks/010-user-specific-conversation-history/**)",
"Grep(/Users/billchirico/Developer/bill-bot/.auto-claude/worktrees/tasks/010-user-specific-conversation-history/**)",
"Read(/Users/billchirico/Developer/bill-bot/.auto-claude/worktrees/tasks/010-user-specific-conversation-history/.auto-claude/specs/010-user-specific-conversation-history/**)",
"Write(/Users/billchirico/Developer/bill-bot/.auto-claude/worktrees/tasks/010-user-specific-conversation-history/.auto-claude/specs/010-user-specific-conversation-history/**)",
"Edit(/Users/billchirico/Developer/bill-bot/.auto-claude/worktrees/tasks/010-user-specific-conversation-history/.auto-claude/specs/010-user-specific-conversation-history/**)",
"Read(/Users/billchirico/Developer/bill-bot/.auto-claude/**)",
"Write(/Users/billchirico/Developer/bill-bot/.auto-claude/**)",
"Edit(/Users/billchirico/Developer/bill-bot/.auto-claude/**)",
"Glob(/Users/billchirico/Developer/bill-bot/.auto-claude/**)",
"Grep(/Users/billchirico/Developer/bill-bot/.auto-claude/**)",
"Bash(*)",
"WebFetch(*)",
"WebSearch(*)",
"mcp__context7__resolve-library-id(*)",
"mcp__context7__get-library-docs(*)",
"mcp__graphiti-memory__search_nodes(*)",
"mcp__graphiti-memory__search_facts(*)",
"mcp__graphiti-memory__add_episode(*)",
"mcp__graphiti-memory__get_episodes(*)",
"mcp__graphiti-memory__get_entity_edge(*)"
]
}
}
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
node_modules/
.env
*.log

# Auto Claude data directory
.auto-claude/
Loading