# Reported issues for node9

Pod holds 11 of 11 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to [node9](/mcp/node9).

## Most discussed

### [Bug] Dashboard "Active Shields" panel stuck on "Loading…"

## Description

The browser dashboard "Active Shields" panel is permanently stuck on "Loading…" even when shields are configured and active. The daemon never emits the `shields-status` SSE event that the dashboard JS listens for.

## Steps to reproduce

1. Run `node9 init` to create default config
2. Configure shields in `~/.node9/shields.json`:
```json
{"active": ["filesystem", "postgres"]}
```
  3. Run node9 daemon --openui
  4. Observe the "Active Shields" panel in the browser dashboard…

[Read the thread](https://github.com/node9-ai/node9-proxy/issues/37) · 2026-03-24 · closed · external user · 6 comments

### ~/.node9/mcp-pins.json not seeded at install; no repo-local pin file

## Summary

`~/.node9/mcp-pins.json` is created on first MCP gateway connection, not at `node9 install` time. Tooling that asserts pin presence fails on clean install until at least one MCP-routed call has been made per server.

## Impact

- New repo onboarding: integrity checks warn about unpinned MCP servers until the operator manually round-trips each one.
- No repo-local pin file. `~/.node9/mcp-pins.json` is per-machine; teammates re-pin independently. Pins cannot be committed for review.…

[Read the thread](https://github.com/node9-ai/node9-proxy/issues/179) · 2026-05-16 · closed · external user · 5 comments

### feat: verdict-only mode for node9 check — let Claude Code render the inline approval prompt

## Problem

We're running a Claude Code-based agent in an enterprise environment with Node9 as the PreToolUse policy gatekeeper. On `review` verdicts the current flow blocks the hook process waiting for a terminal approver via `node9 monitor`, which:

- Freezes the Claude session for the duration of human think time — the hook is what's waiting, and Claude is waiting on the hook.
- Races Claude Code's 60s hook timeout — slow approval = guillotined prompt.
- Forces the user to context-switch to…

[Read the thread](https://github.com/node9-ai/node9-proxy/issues/209) · 2026-06-16 · closed · external user · 4 comments

### setupCodex no longer wires native Codex hooks; warning text is stale

## Summary

In Node9 `1.21.5`, `setupCodex` only wires MCP and prints:

> Codex does not yet support native pre-execution hooks. MCP proxy wrapping is the only supported protection mode for Codex. Native bash and file operations are not monitored.

This warning is factually wrong. Codex ships native hooks (`PreToolUse`, `UserPromptSubmit`, `PostToolUse`, etc.) per https://developers.openai.com/codex/hooks, enabled by default.

## Where

`node_modules/node9-ai/dist/cli.js:6826` (1.21.5, pnpm…

[Read the thread](https://github.com/node9-ai/node9-proxy/issues/178) · 2026-05-16 · closed · external user · 4 comments

### [Bug] Node9 daemon is silently failing (since version 1.19.0?)

## Description

After updating to v1.19.0, the web dashboard at http://127.0.0.1:7391 returns HTTP 404 (Not Found). Running `node9 doctor` reports that the daemon is _not_ running.

Starting the daemon in background mode (`node9 daemon start -b`) appears to succeed and `node9 daemon status` reports it as running, but `node9 doctor` still reports that the daemon is _not_ running.

## Steps to reproduce

1. Update Node9 to v1.19.2 (via Homebrew)
2. Run `node9 daemon start -b`
3. Run `node9 daemon…

[Read the thread](https://github.com/node9-ai/node9-proxy/issues/162) · 2026-05-08 · closed · external user · 4 comments

### [Bug] Windows paths in settings.json hooks break Claude Code on Git Bash

## Description

   Node9-proxy writes Windows paths with backslashes and unquoted spaces into
   `%USERPROFILE%\.claude\settings.json` hooks. Claude Code executes hooks via
   Git Bash, which cannot parse `C:\Program Files\...` — it interprets the                                                                                                                                                                                                                                  
   colon as a command…

[Read the thread](https://github.com/node9-ai/node9-proxy/issues/185) · 2026-05-20 · closed · external user · 3 comments

### [Bug] support Windows (ENOENT when spawning node9 subprocess)

On Windows, spawn("node9", ["daemon"]) fails with ENOENT (error code -4058) because the actual executable is node9.cmd. Node.js child_process.spawn() without { shell: true } does not resolve .cmd/.ps1 wrappers on Windows.

Fix:
Replace bare spawn("node9", ["daemon"], ...) with spawn(process.execPath, [process.argv[1], "daemon"], ...) at three call sites in src/cli.ts:

1. autoStartDaemonAndWait() (~line 170)
2. daemon --openui handler (~line 1048)
3. daemon --background handler (~line 1060)…

[Read the thread](https://github.com/node9-ai/node9-proxy/issues/41) · 2026-03-25 · closed · external user · 3 comments

### No uninstall command or cleanup on npm uninstall

### Problem

There is no method to uninstall node9. `npm uninstall -g @node9/proxy` removes only the npm package. It does not:

- Remove hook entries added to `~/.claude/settings.json` by `node9 addto claude`
- Remove hook entries added to Gemini CLI or Cursor configurations
- Reverse MCP server wrapping applied during `addto`
- Stop the running daemon
- Remove the `~/.node9/` directory (config, audit log, shields, PID file)

After `npm uninstall`, the orphaned hook entries in settings.json…

[Read the thread](https://github.com/node9-ai/node9-proxy/issues/30) · 2026-03-22 · closed · external user · 2 comments

## Most recent

### [Bug] v1.1.2: argument parser consumes flags meant for wrapped command

## Description

Node9 v1.1.2 intercepts flags (e.g. `-y`, `-config`) that are meant for the wrapped command, instead of passing them through. This breaks most MCP server configurations that use `npx -y` or pass flags to the underlying binary.

## Steps to reproduce

1. Configure an MCP server wrapped by node9:
    ```json
    { "command": "node9", "args": ["npx", "-y", "@zereight/mcp-gitlab"] }
2. Run node9 npx -y @zereight/mcp-gitlab
3. Observe node9 rejects -y as its own unknown option…

[Read the thread](https://github.com/node9-ai/node9-proxy/issues/36) · 2026-03-24 · closed · external user · 1 comment

### [Bug] Node9 proxy wrapper breaks stdio MCP servers — banner output on stdout corrupts JSON-RPC stream

## Description

When Node9 wraps MCP server commands in `~/.claude.json` (via `node9 addto claude`), stdio-based MCP servers fail to connect. Node9 writes its `🚀 Node9 Proxy Active: Monitoring [...]` banner to **stdout**, which corrupts the JSON-RPC stream that Claude Code's MCP
client expects to be pure JSON.

Additionally, when using the hooks-only approach (without wrapping), MCP tool calls are intercepted by PreToolUse/PostToolUse hooks (confirmed in `hook-debug.log`) but are **not written…

[Read the thread](https://github.com/node9-ai/node9-proxy/issues/33) · 2026-03-24 · closed · external user · 1 comment

### PreToolUse/PostToolUse hooks show 'hook error' in Claude Code despite exit 0 and successful execution

## Environment
- **Node9 version:** 1.0.15
- **Claude Code version:** 2.1.81
- **Platform:** Windows 11 Pro 10.0.22621
- **Node.js:** v24.13.1

## Problem

After installing node9 and configuring hooks via `node9 addto claude`, every tool call in Claude Code displays "hook error" for both PreToolUse and PostToolUse:

```
PreToolUse:Bash hook error
PostToolUse:Bash hook error
PreToolUse:Read hook error
PostToolUse:Read hook error
PreToolUse:WebFetch hook error
PostToolUse:WebFetch hook error
```…

[Read the thread](https://github.com/node9-ai/node9-proxy/issues/29) · 2026-03-22 · closed · external user · 2 comments

The remaining reports are on [the project's issue tracker](https://github.com/node9-ai/node9-proxy/issues).
