AI tooling security
Security controls for CLI, MCP, Skills, and machine-readable docs.
Threat model highlights
- SSRF via tool parameters — rejected
- Path traversal / absolute private paths — rejected
- Arbitrary shell or plugin execution — not offered
- App Secret leakage into clients or Skills — forbidden
- False product or SDK availability claims — blocked by status sources
Tokens and secrets
Mint tokens only through the token service with scoped claims. Never embed App Secrets in Android starters or MCP responses. CLI redacts tokens unless explicitly requested.
MCP boundaries
- stdio preferred
- HTTP loopback-only by default
- Request and output size limits
- Read-only tools: nothing in your account can be changed through MCP
Skills supply chain
Install scripts support dry-run, destination display, overwrite confirmation, and backup. They never alter global configuration silently.
Source references
docs/website/WEBSITE_STAGE_D4_3_TOOLING_SECURITY_REVIEW.md
Was this page helpful?