charter: separate the blocked forge MCP server from the working GITEA_TOKEN #531
Reference in New Issue
Block a user
Delete Branch "charter/forge-mcp-vs-token"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why
Two workers reported having working forge access. That looked like it contradicted the charter:
I measured it. The charter is right and the workers were right. They are talking about two different credentials, and the wording did not separate them.
curlto$GITEA_HOST/api/v1/repos/fleet/fleetd/pullsGITEA_TOKEN, injected per spawnmcp__gitea__*tools that leak in from the operator's user-scope~/.claude.json.claude/skills/implementer/SKILL.mdstep 5 (lines 96-117) tells the worker to use the first route, and says the token "can create a PR but cannot merge". So opening its own PR is part of a worker's job and it really can do it.The cost of leaving it
This is an ambiguity with a consequence, not a stale line. A worker that reads "any forge tools it appears to have hold a blocked credential and fail" can reasonably conclude it cannot reach the forge at all, and skip step 5 — which is the one step the lead depends on, because the PR body is where a report survives a lost reply. The failure would be quiet: a pushed branch, no PR, and a worker that believes it followed the charter.
The same reading error is available to a lead: seeing "forge tools fail", a lead could disbelieve a worker that correctly reports its own PR URL.
The change
Two sentences, both in the canonical block. Each now names the MCP server specifically and says the injected token is a separate, working route.
Primary, step 6 — Verify yourself:
Member, step 5 — Report honestly:
No behaviour changes. No code changes. 9 insertions, 4 deletions, one file.
Propagation
CLAUDE.md's own rule requires the canonical block and the wiki template to stay byte-identical. Done and verified with the script fromCLAUDE.md:The wiki is a submodule with its own remote, so its commit is separate:
d02a55donwiki'smain, pushed and verified by ref (git ls-remote --heads origin main→d02a55da4478, matching localHEAD) rather than by exit code — a wiki push to the wrong branch name is a silent no-op here.The submodule pointer stays unstaged in this PR, per the repo rule that
wiki/is never committed. OnlyCLAUDE.mdis staged.What this does not claim
I have not re-tested the blocked MCP credential myself this session. The claim that it fails every call is the existing charter's, unchanged by this PR — I am only narrowing which thing it refers to. If someone wants that half re-measured, it needs its own probe with a request that cannot succeed on its merits, so a rejection can only mean the block.