docs: freeze hosted MCP security boundary - #51
Conversation
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Uh oh!
There was an error while loading. Please reload this page.
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Documents the source contract introduced by the cAPI MCP/direct-proxy security remediation so future work cannot rely on chat history or comments as the security control.
Covers hosted-production local-process prohibition, registry auth, direct-proxy internal auth, fail-closed configuration, child environment isolation, remote-MCP expectations and required deployed negative verification.
Docs only; does not claim live
capi.veklom.comhas deployed the source fix.