# Reported issues for heliograph

Pod holds 5 of 5 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to [heliograph](/mcp/heliograph).

## Most discussed

### fix: manifests send users to heliograph.io, and a test pins the old host

Four shipped manifests still name `heliograph.dbhq.uk` as the homepage or documentation. That host's apex now 301s to heliograph.io, the commercial site, so a user who clicks through from the plugin, the MCP registry, npm or the `.mcpb` bundle lands on a product page instead of the toolkit docs. The SKILL.md links and one CLI message reach docs.heliograph.io, but only through a redirect. And the coherence test requires the old host in SKILL.md, so fixing the links breaks the build.…

[Read the thread](https://github.com/heliograph-io/heliograph/issues/151) · 2026-09-24 · open · outside contributor · 1 comment

### feat(cli,mcp): `heliograph cancel [id]` and `heliograph stop`

There is no CLI verb or MCP tool to cancel a running step or stop the station loop. SKILL.md fills the gap by telling the agent to hand-edit `station/request`, commit and push. That contradicts the skill's own rule against editing files instead of using the CLI, and commit-and-push means nothing on the share, bundle, object store or relay transports. An agent that needs to kill a runaway step on those transports has no way to do it.

**Evidence**
- `skills/heliograph/SKILL.md:144-149`: "set…

[Read the thread](https://github.com/heliograph-io/heliograph/issues/153) · 2026-09-24 · closed · outside contributor · 0 comments

### fix: the flagship `net-probe` example is refused, for the wrong reason

The example every doc leads with, `heliograph send net-probe`, does not resolve on a stock station: `run.sh` registers the step as `net`. The station then hides the real cause. `step_mode` throws away the "unknown step" exit, so the refusal reads "step 'net-probe' declares no mode ()". `status` and `watch` never print the `reason:` field, so the user sees generic advice about `--allow-actions` and `CONFIRM=yes`, and `status` says "Its reason is above" when it is not.

**Evidence**
-…

[Read the thread](https://github.com/heliograph-io/heliograph/issues/150) · 2026-09-24 · closed · outside contributor · 0 comments

### fix(mcp): `heliograph_send` requests never expire and carry no target

The MCP `heliograph_send` tool builds its request by hand and leaves out three fields the CLI sets: `Target`, `Expires` and `Mode`. It also skips `Validate()`. The CLI's own comment says why the first two matter: without them a request lifted out of a transport repo stays valid for ever, and a replayed destructive step runs with every gate already satisfied. An agent driving heliograph over MCP gets none of that protection.

**Evidence**
- `cmd/heliograph/mcptools.go:121-127`: `wire.Request`…

[Read the thread](https://github.com/heliograph-io/heliograph/issues/149) · 2026-09-24 · closed · outside contributor · 0 comments

### A blocked port is diagnosed as a credential problem, and 443 is never mentioned

Both git schemes are already supported and diagnosed: `tp_preflight` branches on the remote (`git@*|ssh://*` against `https://*`), reports the ssh-agent state with four outcomes and remedies, and reports the token mechanism for https by kind and length. That half is done and this issue is not about adding it.

**The gap is the network layer underneath it.** An estate that blocks outbound 22 is ordinary, and it is exactly the estate this tool is for.

**What the operator sees today.**…

[Read the thread](https://github.com/dbhq-uk/heliograph/issues/66) · 2026-09-10 · closed · 0 comments

## Most recent

The remaining reports are on [the project's issue tracker](https://github.com/heliograph-io/heliograph/issues).
