| Version | Supported |
|---|---|
| 0.1.x | Yes |
Treat MCP metadata, tool descriptions, outputs, and generated probes as untrusted input.
Tool-Semantics must not automatically execute discovered tools in the MVP.
Please report security issues privately via GitHub Security Advisories. Do not open a public issue for vulnerabilities that could enable remote code execution, secret leakage, or unsafe tool invocation.
We aim to acknowledge reports within 7 days.