fix(security): stop leaking Python tracebacks to MCP clients

Error handlers in execute_task, fix_skill, and upload_skill returned
traceback.format_exc() to MCP clients, exposing internal file paths,
code structure, and potentially sensitive details. The full traceback
is already logged server-side via logger.error(exc_info=True).

Remove the traceback field from client-facing error responses and
clean up the unused traceback import.

Closes #19

Made-with: Cursor
This commit is contained in:
xzq.xu 2026-03-26 14:01:03 +08:00 • committed by Dennis-yxchen
parent f89ea89ffb
commit af1eb5bbe6

View file

@ -22,7 +22,6 @@ import json
import logging
import os
import sys
import traceback
from pathlib import Path
from typing import Any, Dict, List, Optional
@ -597,7 +596,7 @@ async def execute_task(
except Exception as e:
logger.error(f"execute_task failed: {e}", exc_info=True)
return _json_error(e, status="error", traceback=traceback.format_exc(limit=5))
return _json_error(e, status="error")
@mcp.tool()
@ -818,7 +817,7 @@ async def fix_skill(
except Exception as e:
logger.error(f"fix_skill failed: {e}", exc_info=True)
return _json_error(e, status="error", traceback=traceback.format_exc(limit=5))
return _json_error(e, status="error")
@mcp.tool()
@ -889,7 +888,7 @@ async def upload_skill(
except Exception as e:
logger.error(f"upload_skill failed: {e}", exc_info=True)
return _json_error(e, status="error", traceback=traceback.format_exc(limit=5))
return _json_error(e, status="error")
def run_mcp_server() -> None:
"""Console-script entry point for ``openspace-mcp``."""