You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
test(mcp): security suite for the MCP server #1138
Every write form is refused before reaching the driver: INSERT / UPDATE / DELETE / MERGE / DDL / GRANT, WITH ... DELETE, SELECT ...; DROP ..., EXPLAIN ANALYZE of a write, COPY, CALL, DO, SQLite ATTACH / non-allow-listed PRAGMA.
Even when the classifier is bypassed (test hook), the read-only session refuses a write on real SQLite and on Postgres in CI (if a Postgres service is available).
No secret ever appears in any tool or resource output (fuzz all tools on connections with password, SSH key and URL credentials).
Connections with access Off are invisible to every tool.
Token: missing / wrong token is refused; endpoint file has 0600 permissions on Linux / macOS.
Timeout and row limit are enforced; huge cells are truncated.
Refusing write forms before the driver is the right layer. Worth adding argument level injection cases too, not just statement shapes, since agents produce weird value placements. Recording every refused query with the rule that caught it makes the suite double as an audit log.
WITH ... DELETE,SELECT ...; DROP ...,EXPLAIN ANALYZEof a write,COPY,CALL,DO, SQLiteATTACH/ non-allow-listed PRAGMA.Part of #1133.