I'm Nervous About Giving an AI Tool Access to My Repos
What the gitaiflow Claude Desktop extension can and can't touch, and the safeguards that keep it inside the folders you choose.
CBConnecting an assistant to your machine through MCP is convenient, and it should make you slightly uneasy. An MCP server isn't a website. It's a program running on your computer, with your user's permissions, doing what a language model asks it to do.
So before I connect anything that touches my repositories, I ask three questions. What can it reach? What can it run? And where does my code go afterwards? Here's how the gitaiflow extension for Claude Desktop answers each.
1. What It Can Reach: Only the Workspaces You Pick
When you install the extension, you must choose one or more allowed workspaces, which are folders that contain your Git repositories. It's a required setting, so there is no "allow everything" default.
Every request then goes through the same checks:
- The requested path is resolved to its real location, so
..segments and symlinks can't be used to step outside an allowed folder. - If the resolved path isn't inside an allowed workspace, the request is refused.
- The path must exist and must be the root of a Git repository, not a subfolder and not a plain directory.
- If several workspaces match a repository name, it asks for an absolute path instead of guessing.
A practical tip: choose the folder that holds your projects, not your home directory. Narrow is better.
2. What It Can Run: Six Tools, No Shell
The extension exposes six tools: change summary, last summary, changelog, release notes, usage, and model list. None of them takes a command. Each one maps to a fixed gitaiflow action, and what Claude supplies are values such as a repository path or a date range. The server runs the binary directly with an argument list, not through a shell, and every run has a timeout and an output size limit.
It does write files, and you should know which. It saves its summaries in a change-summary/ folder inside the repository, and it writes CHANGELOG.md or RELEASE_NOTES.md when you ask for those. It doesn't edit your source files.
3. Where Your Code Goes
The extension uses your own AI provider and key, set in ~/.gitaiflow/config.env. Your code changes are sent only to the endpoint you configured, so with a local model nothing leaves your machine. Telemetry is switched off for every run the extension starts.
Two things still deserve a mention:
- Claude sees what the tools return. A summary describes your code, and that text becomes part of the conversation and counts toward Claude's context and usage.
- Your configured provider sees the diff. If that provider is hosted, the diff goes there, which is the same trade-off as any other use of
gitaiflow.
4. If You Run the Server Over HTTP
Developers who run the MCP server over HTTP instead of through the extension get two more controls. Requests need a bearer token, which is compared in constant time, and a rate limit applies per token: 5 requests per 60 seconds by default, adjustable through settings. The /health endpoint is the only one that skips both.
Want the Full Picture?
This post covers the safety model. For setup and the full list of MCP settings, see the gitaiflow documentation ↗.
What I'd Tell You Before You Connect Any MCP Server
- Grant the smallest folder that works. An allow-list only helps if it's narrow.
- Prefer tools with fixed actions over tools that take commands. What a tool can't be asked to do, it can't be tricked into doing.
- Read the tool's outputs as data leaving your machine, because they are. Whatever a tool returns goes into the conversation, so check what that includes.