KamoCRM

A workstation probe that never prints the MCP token

FeatureKlusterServices
Shipped
September 28, 2026 at 6:35 AM UTC
Author
Kamo
Commit
bb41ccb

SP11's acceptance read an AI workstation's descriptor and probed its MCP bridge by hand, and one diagnostic line printed a live bearer token into a session transcript (SP11 Task 30 review, finding 2). canary/workstation-probe.sh does both. describe prints the descriptor with the token as "<present>" or null (--refresh mints a new one); probe runs initialize, the tool names, a screenshot's type and a wrong token from an ephemeral container in the Tool Plane's pod, and every line it prints, its errors included, is masked. The token lives in a shell variable and the probe's stdin only. The tests fake kubectl with a known token and run the generated probe with curl against a local bridge.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing