Skip to content

test(mcp): security suite for the MCP server #1138

Description

@ZhuchkaTriplesix
  • Every write form is refused before reaching the driver: INSERT / UPDATE / DELETE / MERGE / DDL / GRANT, WITH ... DELETE, SELECT ...; DROP ..., EXPLAIN ANALYZE of a write, COPY, CALL, DO, SQLite ATTACH / non-allow-listed PRAGMA.
  • Even when the classifier is bypassed (test hook), the read-only session refuses a write on real SQLite and on Postgres in CI (if a Postgres service is available).
  • No secret ever appears in any tool or resource output (fuzz all tools on connections with password, SSH key and URL credentials).
  • Connections with access Off are invisible to every tool.
  • Token: missing / wrong token is refused; endpoint file has 0600 permissions on Linux / macOS.
  • Timeout and row limit are enforced; huge cells are truncated.

Part of #1133.

Activity

  1. added
    testsTheme parser epic
    coreCore library logic and services
    P2Medium priority / Parity & Refactoring
    on Oct 8, 2026
  2. ZhuchkaTriplesix commented on Oct 8, 2026

    @ZhuchkaTriplesix
    MemberAuthor

    Сделано в #1142 (смержен в dev).

  3. cc-bb-aa commented on Oct 9, 2026

    @cc-bb-aa

    Refusing write forms before the driver is the right layer. Worth adding argument level injection cases too, not just statement shapes, since agents produce weird value placements. Recording every refused query with the rule that caught it makes the suite double as an audit log.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P2Medium priority / Parity & RefactoringcoreCore library logic and servicestestsTheme parser epic

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions