Skip to content

Validate MCP server command against allowlist #651

@bug-ops

Description

@bug-ops

Parent: #623

crates/zeph-mcp/src/client.rs:40-51 — MCP server commands from config executed without validation. Validate against allowlist or require explicit user confirmation for unknown commands.

Metadata

Metadata

Assignees

No one assigned

    Labels

    P1Important prioritymcpMCP client/serversecuritySecurity hardeningsize/M

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions