-
Notifications
You must be signed in to change notification settings - Fork 92
Add read-only MCP boundary and path-containment regression tests #226
Copy link
Copy link
Open
Labels
area:mcpMCP client/server packagesMCP client/server packagescommunity-ownedSuitable for community ownershipSuitable for community ownershipdifficulty:advancedAdvanced / high-context workAdvanced / high-context workintegration:mcpModel Context ProtocolModel Context Protocolpriority:p1High priorityHigh prioritystatus:readyReady for contributorsReady for contributorssupport:supportedSupported package/surfaceSupported package/surfacetestingTests and test infrastructureTests and test infrastructure
Milestone
Description
Metadata
Metadata
Assignees
Labels
area:mcpMCP client/server packagesMCP client/server packagescommunity-ownedSuitable for community ownershipSuitable for community ownershipdifficulty:advancedAdvanced / high-context workAdvanced / high-context workintegration:mcpModel Context ProtocolModel Context Protocolpriority:p1High priorityHigh prioritystatus:readyReady for contributorsReady for contributorssupport:supportedSupported package/surfaceSupported package/surfacetestingTests and test infrastructureTests and test infrastructure
Contribution lane: testing / mcp
Difficulty: advanced
Ownership: community-owned
Priority: p1
Milestone: Evidence v2 & CI
Labels:
testing,area:mcp,integration:mcp,community-owned,status:ready,difficulty:advanced,priority:p1,support:supportedBaseline: agent-inspect@6.17.1 → 6.18.0 niche launch
Problem
Read-only MCP needs regression tests for boundary and path-containment (no writes, no escape from allowed roots).
Why it matters
MCP exposure is high-risk; niche launch requires hard regressions.
Proposed scope
Out of scope
Suggested files
Acceptance criteria
Validation commands
Privacy / network notes
Local only. No egress. Synthetic paths.
Contributor instructions
Comment first. Prefer table-driven cases.
Maintainer-review boundary
Maintainers own MCP security boundary changes.