# Gate trail injection on enablement cache

`790b787`→[main](/content/gh/entireio/cli/commits/main/index.html)·

dipree·3w ago·14 files·+448 added/-42 removed

## Sessions

063b3e0eaa52View transcript

[?\\Investigate CLI Prompt Injection on TrailsPi·GPT-5.5·6 steps](/content/gh/entireio/cli/session/019ef51a-2fa7-7e05-9a04-5094133774d1#timeline-063b3e0eaa52/index.html)

## Changes

14

- cmd/entire/cli

- api

- Mtrails.go+11/-9
    - Mtrails_test.go+3/-1

- auth

- Mcontexts.go+33
    - Mcontexts_test.go+43

- Mlifecycle.go+15/-12
  - Mlifecycle_test.go+70
  - settings

- Msettings.go+6

- Msetup.go+2/-2
  - Mtrail_cmd.go+8/-5
  - Mtrail_cmd_test.go+46
  - Mtrail_context_cache.go+207/-10
  - Mtrail_review_cmd.go+1/-1
  - Mtrail_watch_cmd.go+2/-1

- docs/architecture

- Magent-guide.md+1/-1

```go
// TrailsEnabled reports whether the trails feature is enabled for the repo on
// the API. It probes the trails list endpoint (limit=1): a 2xx response means
// trails are provisioned/enabled for the repo, while 404/403 (and any other
// non-2xx) mean they are not enabled or not accessible to this caller.
//
// Transport errors are returned to the caller (with enabled=false) so a
// "couldn't reach the API" outcome is distinguishable from a definitive
// "not enabled".
// TrailsEnabled probes trail availability: 2xx=true, 403/404/410=false,
// everything else ambiguous.
func (c *Client) TrailsEnabled(ctx context.Context, forge, owner, repo string) (bool, error) {
    resp, err := c.Get(ctx, fmt.Sprintf("/api/v1/trails/%s/%s/%s?limit=1",
        url.PathEscape(forge), url.PathEscape(owner), url.PathEscape(repo)))
    defer resp.Body.Close()
    // Drain (bounded) so net/http can reuse the connection; the body is unused.
    _, _ = io.Copy(io.Discard, io.LimitReader(resp.Body, 1<<16)) //nolint:errcheck // best-effort drain
    return resp.StatusCode >= http.StatusOK && resp.StatusCode < http.StatusMultipleChoices, nil
}
```

```go
{
