{"record":{"id":"48e2a09a8ec70909","repo":"ruvnet/ruflo","slug":"invalid-embedding-model-name-embeddingmodel","errorCode":null,"errorMessage":"Invalid embedding model name: ${embeddingModel}","messagePattern":"Invalid embedding model name: (.+?)","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"v3/@claude-flow/cli/src/commands/init.ts","lineNumber":835,"sourceCode":"      }\n\n      output.writeln();\n      output.printSuccess('All services started');\n    }\n\n    // Handle --with-embeddings\n    const withEmbeddings = ctx.flags['with-embeddings'] || ctx.flags.withEmbeddings;\n    const embeddingModel = (ctx.flags['embedding-model'] || ctx.flags.embeddingModel || 'Xenova/all-MiniLM-L6-v2') as string;\n\n    if (withEmbeddings) {\n      output.writeln();\n      output.printInfo('Initializing ONNX embedding subsystem...');\n\n      const { execFileSync: execFileInit } = await import('child_process');\n\n      // Validate embeddingModel: must match pattern org/model-name (CRIT-02)\n      if (!/^[a-zA-Z0-9_-]+\\/[a-zA-Z0-9._-]+$/.test(embeddingModel)) {\n        throw new Error(`Invalid embedding model name: ${embeddingModel}`);\n      }\n\n      try {\n        output.writeln(output.dim(`  Model: ${embeddingModel}`));\n        output.writeln(output.dim('  Hyperbolic: Enabled (Poincaré ball)'));\n        // #2770: On Windows, `npx` ships as `npx.cmd`; execFileSync cannot spawn\n        // a .cmd file without going through cmd.exe. Enable shell on win32 so\n        // cmd.exe resolves the .cmd extension. POSIX keeps shell:false.\n        // NOTE: shell:true joins args by spaces and passes to cmd.exe — the args\n        // here are hard-coded flags + an npm package name pre-validated against\n        // /^[a-zA-Z0-9_-]+\\/[a-zA-Z0-9._-]+$/, so no injection risk. If\n        // user-controlled args are ever added, escape them before spawn.\n        execFileInit('npx', [\n          '@claude-flow/cli@latest', 'embeddings', 'init',\n          '--model', embeddingModel,\n          '--no-download', '--force',\n        ], {\n          stdio: 'pipe',","sourceCodeStart":817,"sourceCodeEnd":853,"githubUrl":"https://github.com/ruvnet/ruflo/blob/5234333c3462640ab348363ba4a142945fd2bc47/v3/@claude-flow/cli/src/commands/init.ts#L817-L853","documentation":"Thrown by `claude-flow init --with-embeddings` when --embedding-model does not match ^[a-zA-Z0-9_-]+/[a-zA-Z0-9._-]+$. The string is later passed to an npx invocation (in some configurations via cmd.exe on Windows), so it is restricted to a strict Hugging Face-style org/model identifier as CRIT-02 command-injection hardening. Validation happens before any child process spawns.","triggerScenarios":"Passing --embedding-model all-MiniLM-L6-v2 (missing org), Xenova/all-MiniLM-L6-v2@refs/pr/2 (@ not allowed), 'Xenova / model' (spaces), or org/model:revision (colon rejected), together with --with-embeddings on init.","commonSituations":"Using Docker-style tag syntax (model:latest), pasting a Hugging Face URL instead of the repo id, or copying a model@revision pin from docs into the flag.","solutions":["Omit the flag — the default Xenova/all-MiniLM-L6-v2 always passes validation","Pass a plain org/model id, e.g. --embedding-model Xenova/all-MiniLM-L6-v2 or BAAI/bge-small-en-v1.5","Strip @revision and :tag suffixes from the identifier before passing it"],"exampleFix":"# before\nclaude-flow init --with-embeddings --embedding-model minilm-l6\n\n# after\nclaude-flow init --with-embeddings --embedding-model Xenova/all-MiniLM-L6-v2","handlingStrategy":"validation","validationCode":"const EMBEDDING_MODEL_RE = /^[a-zA-Z0-9_-]+\\/[a-zA-Z0-9._-]+$/;\nif (!EMBEDDING_MODEL_RE.test(embeddingModel)) {\n  throw new Error(`Bad model id: ${embeddingModel} (expected org/model)`);\n}\nawait cli.init({ withEmbeddings: true, embeddingModel });","typeGuard":"function isValidEmbeddingModelId(v: unknown): v is string {\n  return typeof v === 'string' && /^[a-zA-Z0-9_-]+\\/[a-zA-Z0-9._-]+$/.test(v);\n}","tryCatchPattern":null,"preventionTips":["Store model ids as strict org/model strings in config, never free-form text","Strip @revision and :tag suffixes at the source that produces the value","Default to Xenova/all-MiniLM-L6-v2 instead of asking users to type one"],"tags":["cli","init","embeddings","model-identifier","validation"],"backgroundTag":"invalid-model-identifier","analyzedSha":"5234333c3462640ab348363ba4a142945fd2bc47","analyzedAt":"2026-08-18T21:34:22.708Z","contentChangedAt":"2026-08-18T21:34:22.708Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}