Skip to content

[Bug bounty] monk.watcher.remove emits 4 distinct error shapes in 95 min — no error-shape categorisation, no retry-hint, no escalation path #481

Description

@NyxSpecter4

Summary

Today's run produced four failed attempts against monk.watcher.remove within a 95-minute window. Each attempt surfaced a different error shape with no shared categorisation.

Stage

operate

Repro steps

  1. Sign in to Monk as github|236979482 via Cursor MCP login
  2. Issue monk.watcher.remove against the active watcher (3 times within 90 min)
  3. Inspect ~/.monk/agent/store/global/actions/items.json tool:monk.watcher.remove records

Expected

All four attempts resolve to one of: NO_CLOUD_CREDENTIALS / NO_ACTIVE_CLUSTER / REVIEW_TIMEOUT / MANIFEST_LOAD_FAIL — each with a remediation hint.

Actual

  • Four distinct error shapes surfaced in the action store: ('No cloud provider credentials are stored.', 'Watcher removal review timed out.', 'No active remote cluster is available.', 'Failed to load MANIFEST: ===> Reading files...').

Setup

Windows 11, Cursor with Monk coding-agent plugin v0.1.58, agent cursor-vscode, github|236979482, ws_5ce1ff01e80213a86c54b1cb.

Evidence

Attached: monkd-action-store-watcher-remove.json, monkd-action-store-watcher-remove-trace-2026-08-31.txt

Bounty eligibility

  • Signed up at monk.io with GitHub (github|236979482)
  • Used the product (installed plugin and ran it)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions