Reported issues for Carve
Pod holds 5 of 5 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.
Back to Carve.
Most discussed
Define an authorized include root for MCP tools
Problem
The MCP render and conversion tools currently have no include-resolution surface. Enabling reads implicitly would let document text select files from the server host.
Proposed contract
- keep includes disabled unless the tool call supplies an allowed root
- require the server configuration to authorize that root
- use the engine's contained filesystem resolver and all default budgets
- return sanitized warnings and dependency identities
- never derive a root from the server…
Read the thread · 2026-09-15 · closed · outside contributor · 0 comments
Publish and submit carve-mcp to MCP registries and awesome lists
Goal
Publish and list Carve MCP where MCP users discover production-ready servers.
Why this follows the first release
The package is not on npm yet, and the main community list favors working install commands and Glama-backed entries. Submitting an unpublished npx command would create a broken listing.
Checklist
- merge the initial feature and documentation PRs
- publish
@markup-carve/carve-mcpwith npm provenance - verify
npx -y @markup-carve/carve-mcpfrom a…
Read the thread · 2026-09-05 · closed · outside contributor · 0 comments
Add an authenticated Streamable HTTP deployment mode
Problem
The first release supports local stdio only. Shared services need remote transport, authentication, isolation, and operational guidance.
Proposed capability
Add an optional Streamable HTTP deployment mode after the local API stabilizes.
Acceptance criteria
- authentication and authorization are required outside loopback development
- origin/host validation and request-size limits are enabled
- sessions, cancellation, rate limits, and timeouts are documented and tested -…
Read the thread · 2026-09-05 · closed · outside contributor · 0 comments
Add opt-in workspace-scoped document operations
Problem
The initial server accepts source text only. Editing whole projects requires file access, but unrestricted filesystem tools would create an unnecessarily broad trust boundary.
Proposed capability
Add opt-in, workspace-scoped document operations with explicit roots and safe defaults.
Acceptance criteria
- filesystem access is disabled unless roots are configured by the client
- paths are canonicalized and cannot escape an allowed root
- reads and writes have separate…
Read the thread · 2026-09-05 · closed · outside contributor · 0 comments
Expose versioned authoring and rule resources
Problem
Assistants can process Carve documents, but they cannot yet discover the concise human-facing syntax and rule guidance maintained by the project.
Proposed capability
Expose versioned, read-only MCP resources for:
- a concise authoring guide
- the normative rule index
- targeted rule lookup by stable rule ID
- examples for common writing tasks
Keep detailed normative material linked from the concise resources instead of duplicating it in top-level navigation or tool…
Read the thread · 2026-09-05 · closed · outside contributor · 0 comments
Most recent
The remaining reports are on the project's issue tracker.