Reported issues for MCP Debug Recorder
Pod holds 22 of 28 problems reported by people outside the maintainer team. Issues filed by the project's own owners, members and collaborators are excluded entirely — a maintainer's release checklist is not a warning to a prospective user.
Back to MCP Debug Recorder.
Most discussed
[PACKAGING] Restore public npm install and align repository metadata
Problem
The public install path advertised in README.md is broken. Evidence from npm on 2026-05-26: npm view mcp-debug-recorder version returns E404 and says the package was unpublished on 2026-05-17. The repo has no GitHub Release or tag, while the README badges and quick start point users to npx mcp-debug-recorder. package.json also points repository, homepage, and bugs at github.com/oaslananka/mcp-debug-recorder, but the actual repository is `github.com/oaslananka/debug-rec
Read the thread · 2026-05-26 · closed · 15 comments
[SUPPLY CHAIN] Pin Docker image digests and harden workflow installers
Problem
OpenSSF Scorecard reports remaining pinned-dependency gaps even though GitHub Actions are pinned to commit SHAs and action metadata uses supported runtimes. Evidence: code-scanning alerts flag Dockerfile because node:24-bookworm-slim is not pinned by digest, and .github/workflows/security.yml because the pip install zizmor==1.24.1 command is not hash-pinned. Impact: release and security jobs still rely on mutable external artifacts.
Required changes
Pin both Docker stages
Read the thread · 2026-05-26 · closed · 5 comments
[DX] Add dead-code and package-size checks
Problem
The project has good TypeScript and ESLint gates, but no dedicated dead-code or package-size regression checks. Evidence: package.json has format, lint, typecheck, tests, build, audit, and pack dry-run scripts, but no tool that fails on unused exports/files/dependencies or tracks the packed artifact contents/size over time. Impact: a small CLI/MCP package can slowly accumulate unused code, accidental files, or bloated package artifacts.
Required changes
Evaluate a maintained dea
Read the thread · 2026-05-26 · closed · 3 comments
[SONAR] Restore the security quality gate without lowering thresholds
Context snapshot — 2026-07-20
SonarQube Cloud automatic analysis is active for project oaslananka_debug-recorder-mcp. The main-branch quality gate currently reports ERROR because new_security_rating is 3 while the gate requires 1.
Current public project measures:
- 12 vulnerabilities
- 18 code smells
- 0 bugs
- 0 security hotspots
- 0.4% duplicated lines
- maintainability rating A (
1.0) - security rating C (
3.0)
The findings include GitHub Actions lifecycle-script warnings,
Read the thread · 2026-07-20 · closed · 2 comments
[RELEASE] Automate MCP Registry validation after npm verification
Context snapshot — 2026-06-24
docs/release-flow.md states MCP Registry publishing is intentionally separate from npm publishing and should be gated after npm publish verification succeeds. server.json currently uses the identity io.github.oaslananka/debug-recorder-mcp.
Acceptance criteria
- Decide whether registry submission remains manual or becomes a gated GitHub Actions job.
- Verify
server.json.versionandserver.json.packages[].versionafter npm publication. - [ ]
Read the thread · 2026-06-24 · closed · 2 comments
[SECURITY] Publish VEX and SBOM policy for dependency findings
Context snapshot — 2026-06-24
The release workflow already generates SBOM and artifact attestations. Scanner output recommends using VEX-style maintainer decisions when a finding is not exploitable or is dev-only noise.
Acceptance criteria
- Document when a finding must be fixed immediately vs accepted temporarily.
- Document how to classify prod, optional, dev, test-only, and scanner-only findings.
- Add or document a VEX/advisory decision artifact format.
- Release ass
Read the thread · 2026-06-24 · closed · 2 comments
[DOCS] Add ADRs for storage, search, transport, and release decisions
Problem
Major technical decisions are documented narratively but not captured as Architecture Decision Records. Evidence: there is no docs/adr/ directory, while the project has consequential choices around SQLite/FTS5 persistence, Fuse.js reranking, Streamable HTTP hardening, release-please, npm provenance, and MCP Registry metadata. Impact: future maintainers lack durable context for why these choices were made and when to revisit them.
Required changes
Add ADRs under docs/adr/ for a
Read the thread · 2026-05-26 · closed · 2 comments
[TESTING] Enforce coverage, e2e, and fuzz regression gates in GitHub CI
Problem
GitHub CI does not enforce the full test posture described by the repo docs, and Scorecard reports no fuzzing/property-based regression coverage. Evidence: jest.config.js defines coverage thresholds and Azure runs npm run test:coverage plus npm run test:e2e, but .github/workflows/ci.yml runs only npm test and does not run npm run test:e2e. Scorecard alert #9 reports no fuzzer integration. Impact: critical HTTP, import/export, and search edge cases can regress without block
Read the thread · 2026-05-26 · closed · 2 comments
Most recent
[RELEASE] Restore SBOM generation and complete package publication
Context
The debug-recorder-mcp-v1.1.1 GitHub release and GHCR image were created, but the release asset job failed before npm publication. npm sbom --sbom-format=cyclonedx rejected the dependency graph after version-scoped parent overrides were added for two brace-expansion compatibility lines.
Observed release error:
ESBOMPROBLEMS
invalid: brace-expansion@5.0.7, 1.1.16 required by minimatch@10.2.5
As a result, npm and the MCP Registry do not contain version 1.1.1.
Read the thread · 2026-07-20 · closed · 0 comments
[HTTP] Define an MCP-compliant authorization profile for public remote deployments
Context snapshot — 2026-07-20
The optional Streamable HTTP server is intentionally local-first and currently protects non-loopback binds with an explicit opt-in, a static bearer token, Host and Origin allowlists, and request-size controls. This is appropriate for private networks, VPNs, or an authenticating reverse proxy.
It should not be described as a complete public multi-user authorization solution without a documented MCP/OAuth resource-server profile.
Research goals
- Evaluate th
Read the thread · 2026-07-20 · closed · 0 comments
[PRODUCT] Persist stable completion timestamps and session duration semantics
Context snapshot — 2026-07-20
get_session_context currently calculates duration_ms as Date.now() - created_at for every session. Resolved and abandoned sessions therefore appear to become longer every time they are queried, even though their debugging activity has ended.
Using updated_at as a permanent substitute is also ambiguous because later metadata edits can change it.
Acceptance criteria
- The data model records an explicit immutable completion timestamp such as `clos
Read the thread · 2026-07-20 · closed · 0 comments
[OBSERVABILITY] Align diagnostics with effective runtime configuration
Context snapshot — 2026-07-20
Runtime configuration and diagnostics currently parse boolean environment values differently. HTTP and storage behavior accept true, 1, and yes, while diagnostics report only the literal value true as enabled.
Verified examples:
DEBUG_RECORDER_REMOTE_HTTP=yesenables the runtime setting but diagnostics reportremote_http: false.DEBUG_RECORDER_REDACT_BEFORE_STORE=1enables storage redaction but diagnostics reportredact_before_store: false.
Read the thread · 2026-07-20 · closed · 0 comments
[MCP] Return actionable domain failures as tool execution errors
Context snapshot — 2026-07-20
Tool handlers currently log and rethrow domain failures such as missing session IDs. This can surface recoverable user/model mistakes as protocol-level failures instead of actionable MCP tool results.
The tool annotations also contain at least one misleading destructive classification: remove_search_preset deletes persistent user state but is registered with destructiveHint: false.
Acceptance criteria
- Expected domain failures return MCP tool resu
Read the thread · 2026-07-20 · closed · 0 comments
[STORAGE] Version the backup format and preserve saved search presets
Context snapshot — 2026-07-20
The repository presents export_sessions and import_sessions as backup and migration workflows. The current export payload includes sessions, fixes, and commands, but omits saved_search_presets. Restoring an export therefore does not restore the complete user-managed state.
The import format is also coupled directly to CURRENT_SCHEMA_VERSION, which makes future database migrations likely to reject otherwise valid older backup files.
Acceptance criter
Read the thread · 2026-07-20 · closed · 0 comments
[SEARCH] Make pagination truthful beyond the bounded search window
Context snapshot — 2026-07-20
SearchSchema accepts offsets up to 10,000, but searchSessionsPage() bounds the internal result window to 1,000 records. Once the requested page reaches that boundary, the API can return an empty page or has_more: false even when matching sessions remain.
A controlled dataset with 1,005 matching sessions reproduced the following behavior:
offset: 990, limit: 10returned 10 records withhas_more: falsealthough five matches remained.- `offset: 1000,
Read the thread · 2026-07-20 · closed · 0 comments
[MCP] Enforce output schema compatibility for all export variants
Context snapshot — 2026-07-20
export_sessions currently registers a single ExportSessionsOutputSchema, while the summary execution path returns abbreviated session objects. A direct runtime validation of the generated summary payload fails because fields required by SessionRowSchema are absent.
This violates the public MCP tool contract for clients that validate structuredContent against the advertised outputSchema.
Reproduction
- Create at least one debug session.
- Invo
Read the thread · 2026-07-20 · closed · 1 comment
[DOCS] Add executable client setup recipes and examples
Context snapshot — 2026-06-24
README has Quick Start and generic client setup. Adoption would improve with executable recipes for common MCP host configurations and copy-paste-safe examples.
Acceptance criteria
- Add tested stdio setup examples using
npx debug-recorder-mcp. - Add Streamable HTTP setup examples with auth, host, and origin notes.
- Include safe example debug sessions and search queries.
- Ensure docs avoid unsupported client claims and clearly mark any h
Read the thread · 2026-06-24 · closed · 0 comments
[OBSERVABILITY] Add operational diagnostics and troubleshooting fixtures
Context snapshot — 2026-06-24
The repo has structured logging and a health endpoint, but operational diagnostics can be more actionable for local and containerized usage.
Acceptance criteria
- Document a troubleshooting flow for startup, database, MCP client, HTTP auth, and search issues.
- Add optional diagnostics output that never leaks sensitive values.
- Add fixtures that prove redaction behavior for representative tokens, paths, stack traces, and command output.
- C
Read the thread · 2026-06-24 · closed · 1 comment
[STORAGE] Define local data retention, compaction, and redaction policy
Context snapshot — 2026-06-24
The product stores debug sessions, commands, output, stack traces, environment details, and fix notes in local SQLite. This is valuable but can include sensitive operational data.
Acceptance criteria
- Document retention and backup expectations for local-first usage.
- Add a safe database maintenance plan: VACUUM/compaction, export/import, and schema migration rollback guidance.
- Define how
DEBUG_RECORDER_REDACT_BEFORE_STOREinteracts with ex
Read the thread · 2026-06-24 · closed · 1 comment
[SEARCH] Implement v1.1 search usability roadmap
Context snapshot — 2026-06-24
ROADMAP.md lists v1.1.0 search and usability goals: pagination metadata, saved search presets, related sessions, and Markdown export for incident/postmortem workflows.
Acceptance criteria
-
search_sessionsexposes pagination metadata for large histories. - Saved search presets are designed with schema, storage, and tests.
- Related sessions are grouped by tags, error fingerprints, or similarity signal.
- Optional Markdown export supports
Read the thread · 2026-06-24 · closed · 1 comment
[TESTING] Raise meaningful coverage gates for tool handlers and HTTP transport
Context snapshot — 2026-06-24
Local non-audit quality gates pass, and global coverage is strong. Gaps remain in high-value surfaces:
src/tools/recording-tools.tsline coverage is 41.66%.src/server-http.tsis excluded fromcollectCoverageFromeven though it is security-sensitive.
Acceptance criteria
- Add direct unit coverage for recording tool handlers.
- Re-evaluate whether
server-http.tsshould be included in coverage thresholds or covered through a dedicated thr
Read the thread · 2026-06-24 · closed · 1 comment
[MAINTENANCE] Adopt npm install-script approval policy
Context snapshot — 2026-06-24
npm ci completes, but npm reports install scripts not yet covered by approval:
better-sqlite3@12.8.0install scriptunrs-resolver@1.12.2postinstall script
Acceptance criteria
- Document why each approved install script is required.
- Add deterministic npm script-approval configuration or documented maintainer workflow.
- CI behavior is explicit: either enforce approvals or document why CI currently relies on lockfile and package revi
Read the thread · 2026-06-24 · closed · 1 comment
The remaining reports are on the project's issue tracker.