Reported issues for PG1 Sovereign Threat Intelligence
Pod holds 8 of 8 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.
Back to PG1 Sovereign Threat Intelligence.
Most discussed
sc
@claude Security report only, no code changes: explain exactly how the /api/chat endpoint authorizes privileged actions (APPLY_SURGICAL_PATCH and any other actionType that writes to GitHub, Supabase or Vercel) and the /approve and /decline steps. Specifically: is "isAuthorizedAction" trusted from the request body? Is any secret, token, session or header required, and where is it checked? Could an anonymous internet caller POST to /api/chat and obtain an approval token or open a PR? Also check…
Read the thread · 2026-09-26 · closed · 5 comments
mcp fix1
@claude Make PG1's MCP payment flow conform to the x402 v2 MCP transport spec (specs/transports-v2/mcp.md), as used by @x402/mcp clients. You have no network access, so the spec details are given here.
Scope: api/mcp.mjs and lib/paymentGate.mjs only. Do NOT change /api/ioc, /api/ioc/context or /api/health. Do NOT change any tool names, descriptions or input/output schemas. Do NOT touch server.json.
Required behaviour for tools/call on PAID tools (e.g. get_threat_indicators, get_cve_details,…
Read the thread · 2026-09-28 · closed · 3 comments
Minor fix
@claude Please review and fully fix api/mcp.mjs and api/chat.mjs in this repo, then verify the whole payment flow is consistent end to end. Context:
Both files use a three-tier auth gate: Gumroad license key -> free tier -> x402 micropayment (Base mainnet, $0.01/call). This must stay in that priority order.
The free tier must be OPT-IN via a request header "x-free-tier: 1" — not automatic. A caller with no license key, no payment header, and no x-free-tier header should get a 402…
Read the thread · 2026-09-24 · closed · 1 comment
New bug
@claude Here's a clear, self-contained report you can paste over: New bug found while testing the x402 payment path (separate from the header-formatting issue on my end): With an X-PAYMENT header actually present in the request (even a malformed test one), the request now fails with a 500 instead of returning the generic payment-required message. The Vercel logs show: Code Two distinct issues visible here: My test header was malformed (I sent literally {payment_header} as plain text instead of…
Read the thread · 2026-09-21 · closed · 1 comment
Follow up
@claude Follow-up on the Express compat shim (PR #79): The crash is fixed — /api/mcp no longer times out when an X-PAYMENT header is sent. However, testing shows the request still isn't reaching CDP for payment verification, even with a header present. Evidence: Sent a POST to /api/mcp with a base64-encoded X-PAYMENT header (valid JSON structure, fake/garbage signature and addresses). Response was the same generic -32003 "Payment required" JSON-RPC error as an unauthenticated request. Checked…
Read the thread · 2026-09-21 · closed · 1 comment
Final fixes
@claude In api/mcp.mjs (and check api/chat.mjs/api/chat.mjs's /api/ioc handler too, since it uses the same @x402/express middleware pattern), there's a bug: when a request includes an X-PAYMENT header, the code crashes with TypeError: this.req.header is not a function, thrown inside @x402/express's ExpressAdapter.getHeader. This happens because @x402/express expects a true Express request object (with a .header() method), but these are raw Vercel serverless functions — the request object…
Read the thread · 2026-09-21 · closed · 1 comment
new
@claude Make PG1's MCP payment flow conform to the x402 v2 MCP transport spec (specs/transports-v2/mcp.md), as used by @x402/mcp clients. You have no network access, so the spec details are given here.
Scope: api/mcp.mjs and lib/paymentGate.mjs only. Do NOT change /api/ioc, /api/ioc/context or /api/health. Do NOT change any tool names, descriptions or input/output schemas. Do NOT touch server.json.
Required behaviour for tools/call on PAID tools (e.g. get_threat_indicators, get_cve_details,…
Read the thread · 2026-09-27 · closed · 0 comments
new
@claude In lib/paymentGate.mjs, verifyGumroadLicense currently returns valid:false both for a genuinely bad key and when Gumroad times out or errors with no cached success. Return a distinct reason for the timeout/unreachable case, e.g. reason: 'verification_unavailable'. In api/chat.mjs (/api/ioc), api/mcp.mjs and api/ioc/context.js, when the reason is verification_unavailable, respond 503 with a Retry-After: 5 header and the error "License verification temporarily unavailable, please retry."…
Read the thread · 2026-09-26 · closed · 0 comments
Most recent
The remaining reports are on the project's issue tracker.