Skip to content

v1.1.6

Choose a tag to compare

@tumf tumf released this 04 Aug 05:54
· 8 commits to main since this release

Security

  • Reject persistent git config invocations that can store executable Git configuration.
  • Apply existing hardened policies to common alternate command names such as gawk, gfind, gtar, and bsdtar.
  • Reject command-wrapper and shell-escape tools such as timeout, nice, nohup, setsid, stdbuf, flock, less, vim, and ssh by default.
  • Document that command hardening is best-effort defense in depth, not a complete sandbox.

PyPI: https://pypi.org/project/mcp-shell-server/1.1.6/