[FR] # MCP Security and Dynamic Client Registration #517

Description

@chussenot-believe

MCP Security and Dynamic Client Registration

Description

We appreciate using SourceBot EE for its integration with LLMs and advanced code search capabilities. However, we have several security concerns around the current MCP server implementation that increase the risk of unauthorized data access, exfiltration, and could lead to supply chain compromission.

Note: SourceBot already provides audit logs (see docs), but we request enhanced coverage for MCP-specific events and alerting hooks.

Context and Security Concerns

With the introduction of the MCP Server, SourceBot exposes a set of tools (search_code, list_repos, get_file_source) that are extremely powerful but also carry significant security implications:

  • Uncontrolled third parties - if the MCP server relays extracts (contexts, diffs, enriched prompts) to a remote LLM platform (SaaS, vendor LLM, etc.), it is possible that all or part of the code/documentation/secrets may pass through an uncontrolled third party.
  • Sensitive data exfiltration – attackers can use search_code to locate secrets (e.g., passwords, API tokens, private keys) and then retrieve them with get_file_source.
  • Uncontrolled discoverylist_repos makes it easy to enumerate all repositories and target sensitive ones.
  • Prompt injection / confused-deputy attacks – instructions hidden in indexed files could trick an agent into exfiltrating data through MCP tools.
  • Audit coverage – while audit logs exist, they should be extended with finer-grained MCP actions (tool usage, suspicious query detection) and integrated with alerting.
  • Supply chain exposure – use of unpinned npm execution in the mcp.json configuration (e.g., npx -y @sourcebot/mcp@latest) increases risk of package compromise.

Proposed Solution: Hosted MCP API + Dynamic Client Registration

Overview

We propose implementing a hosted MCP API on SourceBot with Dynamic Client Registration support as defined in the MCP Authorization specification.

Key Benefits

  1. No API Key Storage Required

    • Users don't need to store API keys locally
    • Eliminates risk of key leakage through configuration files
    • Reduces attack surface for credential theft
  2. Granular OAuth Schema Control

    • Administrators can precisely control which OAuth schemas are authorized
    • Better compliance with enterprise AI policies
    • Example: Allow vscode:// but block cursor:// based on security requirements
  3. Enhanced Security Model

    • OAuth-based authentication with proper scopes
    • Temporary access tokens with configurable expiration
    • Centralized revocation capabilities

Technical Implementation

1. Hosted MCP API

  • Deploy MCP server as a hosted service on SourceBot infrastructure
  • Provide secure endpoints for MCP tool access
  • Implement proper authentication and authorization layers

2. Dynamic Client Registration

3. Enterprise Policy Controls

  • Admin dashboard for OAuth schema management
  • Whitelist/blacklist specific client applications
  • Role-based access to different MCP tools
  • Audit logging for all MCP operations

Requested Features

  1. Hosted MCP API

    • Deploy MCP server as a managed service
    • High availability and scalability
    • Secure communication channels
  2. Dynamic Client Registration Support

    • Implement MCP authorization specification
    • OAuth 2.0 integration
    • Client application management
  3. Enterprise Policy Controls

    • OAuth schema allowlist/denylist management
    • Granular tool access permissions
    • Repository and file-level access policies
  4. Query Controls

    • Built-in query filtering and result redaction for common secret patterns
    • Real-time content scanning and sanitization
    • Suspicious query detection and blocking
  5. Supply Chain Protections

    • Pin MCP client dependencies
    • Provide signed releases and/or official container images
    • Regular security updates and vulnerability scanning
  6. Enhanced Auditability & Alerting

    • Extend existing audit logs with detailed MCP tool usage events
    • Provide alerting hooks for suspicious activity
    • Integration with enterprise security tools

Risks by Tool

search_code

What an attacker could do:

  • Run searches for secret patterns (password, token, key, BEGIN RSA PRIVATE KEY, etc.).
  • Extract code snippets and identify patterns in README files or commits to manipulate LLMs (prompt injection).
  • Use broad regex queries to map the entire codebase and find sensitive targets.

Impact:

  • Rapid discovery of secrets, endpoints, and critical paths.
  • Foundation for follow-up attacks (SSRF, cloud account takeover).

Mitigations with Hosted MCP + DCR:

  • OAuth scopes limit search capabilities per client
  • Server-side query validation and filtering
  • Automatic redaction of results containing common secret formats
  • Real-time monitoring and alerting on sensitive queries

list_repos

What an attacker could do:

  • Enumerate all indexed repositories.
  • Identify high-value repos by naming conventions (infra-, prod-, ci) and prioritize attacks.

Impact:

  • Facilitates targeted attacks when combined with search_code and get_file_source.

Mitigations with Hosted MCP + DCR:

  • OAuth scopes restrict repository listing permissions
  • Role-based access controls limit visible repositories
  • Admin policies can hide sensitive repository metadata

get_file_source

What an attacker could do:

  • Download critical files (CI/CD pipelines, configs, scripts, dumps, backups).
  • Extract credentials and historical secrets from old commits or configs.

Impact:

  • Direct leakage of credentials, cloud compromise, CI/CD takeover, and loss of intellectual property.

Mitigations with Hosted MCP + DCR:

  • OAuth scopes control file access permissions
  • Server-side redaction before returning results
  • File/repository allowlists enforced at the API level
  • Real-time content scanning and sanitization

Implementation Roadmap

Phase 1: Hosted MCP API

  • Deploy MCP server as managed service
  • Implement basic OAuth 2.0 authentication
  • Migrate existing API key users

Phase 2: Dynamic Client Registration

  • Implement MCP authorization specification
  • Add client registration and management
  • Enable OAuth schema controls

Phase 3: Enterprise Features

  • Advanced policy controls
  • Enhanced audit and monitoring
  • Integration with enterprise security tools

Conclusion

The MCP server in SourceBot must be treated as a high-risk surface. By implementing a hosted MCP API with Dynamic Client Registration, we can eliminate API key storage risks while providing administrators with precise control over client access and OAuth schemas. This approach enables secure deployment in sensitive environments while maintaining the powerful capabilities that make SourceBot valuable.


Sources & References

Some sources to read:

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions

      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
       blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
      }
      } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
      })();
      (function(){
      try {
      var __m = "github.com";
      var __re = new RegExp('^' + "github\\.com" + '
      
      Skip to content

      [FR] # MCP Security and Dynamic Client Registration #517

      Description

      @chussenot-believe

      MCP Security and Dynamic Client Registration

      Description

      We appreciate using SourceBot EE for its integration with LLMs and advanced code search capabilities. However, we have several security concerns around the current MCP server implementation that increase the risk of unauthorized data access, exfiltration, and could lead to supply chain compromission.

      Note: SourceBot already provides audit logs (see docs), but we request enhanced coverage for MCP-specific events and alerting hooks.

      Context and Security Concerns

      With the introduction of the MCP Server, SourceBot exposes a set of tools (search_code, list_repos, get_file_source) that are extremely powerful but also carry significant security implications:

      • Uncontrolled third parties - if the MCP server relays extracts (contexts, diffs, enriched prompts) to a remote LLM platform (SaaS, vendor LLM, etc.), it is possible that all or part of the code/documentation/secrets may pass through an uncontrolled third party.
      • Sensitive data exfiltration – attackers can use search_code to locate secrets (e.g., passwords, API tokens, private keys) and then retrieve them with get_file_source.
      • Uncontrolled discoverylist_repos makes it easy to enumerate all repositories and target sensitive ones.
      • Prompt injection / confused-deputy attacks – instructions hidden in indexed files could trick an agent into exfiltrating data through MCP tools.
      • Audit coverage – while audit logs exist, they should be extended with finer-grained MCP actions (tool usage, suspicious query detection) and integrated with alerting.
      • Supply chain exposure – use of unpinned npm execution in the mcp.json configuration (e.g., npx -y @sourcebot/mcp@latest) increases risk of package compromise.

      Proposed Solution: Hosted MCP API + Dynamic Client Registration

      Overview

      We propose implementing a hosted MCP API on SourceBot with Dynamic Client Registration support as defined in the MCP Authorization specification.

      Key Benefits

      1. No API Key Storage Required

        • Users don't need to store API keys locally
        • Eliminates risk of key leakage through configuration files
        • Reduces attack surface for credential theft
      2. Granular OAuth Schema Control

        • Administrators can precisely control which OAuth schemas are authorized
        • Better compliance with enterprise AI policies
        • Example: Allow vscode:// but block cursor:// based on security requirements
      3. Enhanced Security Model

        • OAuth-based authentication with proper scopes
        • Temporary access tokens with configurable expiration
        • Centralized revocation capabilities

      Technical Implementation

      1. Hosted MCP API

      • Deploy MCP server as a hosted service on SourceBot infrastructure
      • Provide secure endpoints for MCP tool access
      • Implement proper authentication and authorization layers

      2. Dynamic Client Registration

      3. Enterprise Policy Controls

      • Admin dashboard for OAuth schema management
      • Whitelist/blacklist specific client applications
      • Role-based access to different MCP tools
      • Audit logging for all MCP operations

      Requested Features

      1. Hosted MCP API

        • Deploy MCP server as a managed service
        • High availability and scalability
        • Secure communication channels
      2. Dynamic Client Registration Support

        • Implement MCP authorization specification
        • OAuth 2.0 integration
        • Client application management
      3. Enterprise Policy Controls

        • OAuth schema allowlist/denylist management
        • Granular tool access permissions
        • Repository and file-level access policies
      4. Query Controls

        • Built-in query filtering and result redaction for common secret patterns
        • Real-time content scanning and sanitization
        • Suspicious query detection and blocking
      5. Supply Chain Protections

        • Pin MCP client dependencies
        • Provide signed releases and/or official container images
        • Regular security updates and vulnerability scanning
      6. Enhanced Auditability & Alerting

        • Extend existing audit logs with detailed MCP tool usage events
        • Provide alerting hooks for suspicious activity
        • Integration with enterprise security tools

      Risks by Tool

      search_code

      What an attacker could do:

      • Run searches for secret patterns (password, token, key, BEGIN RSA PRIVATE KEY, etc.).
      • Extract code snippets and identify patterns in README files or commits to manipulate LLMs (prompt injection).
      • Use broad regex queries to map the entire codebase and find sensitive targets.

      Impact:

      • Rapid discovery of secrets, endpoints, and critical paths.
      • Foundation for follow-up attacks (SSRF, cloud account takeover).

      Mitigations with Hosted MCP + DCR:

      • OAuth scopes limit search capabilities per client
      • Server-side query validation and filtering
      • Automatic redaction of results containing common secret formats
      • Real-time monitoring and alerting on sensitive queries

      list_repos

      What an attacker could do:

      • Enumerate all indexed repositories.
      • Identify high-value repos by naming conventions (infra-, prod-, ci) and prioritize attacks.

      Impact:

      • Facilitates targeted attacks when combined with search_code and get_file_source.

      Mitigations with Hosted MCP + DCR:

      • OAuth scopes restrict repository listing permissions
      • Role-based access controls limit visible repositories
      • Admin policies can hide sensitive repository metadata

      get_file_source

      What an attacker could do:

      • Download critical files (CI/CD pipelines, configs, scripts, dumps, backups).
      • Extract credentials and historical secrets from old commits or configs.

      Impact:

      • Direct leakage of credentials, cloud compromise, CI/CD takeover, and loss of intellectual property.

      Mitigations with Hosted MCP + DCR:

      • OAuth scopes control file access permissions
      • Server-side redaction before returning results
      • File/repository allowlists enforced at the API level
      • Real-time content scanning and sanitization

      Implementation Roadmap

      Phase 1: Hosted MCP API

      • Deploy MCP server as managed service
      • Implement basic OAuth 2.0 authentication
      • Migrate existing API key users

      Phase 2: Dynamic Client Registration

      • Implement MCP authorization specification
      • Add client registration and management
      • Enable OAuth schema controls

      Phase 3: Enterprise Features

      • Advanced policy controls
      • Enhanced audit and monitoring
      • Integration with enterprise security tools

      Conclusion

      The MCP server in SourceBot must be treated as a high-risk surface. By implementing a hosted MCP API with Dynamic Client Registration, we can eliminate API key storage risks while providing administrators with precise control over client access and OAuth schemas. This approach enables secure deployment in sensitive environments while maintaining the powerful capabilities that make SourceBot valuable.


      Sources & References

      Some sources to read:

      Activity

      Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

      Metadata

      Metadata

      Assignees

      No one assigned

        Labels

        Type

        No type

        Projects

        No projects

          Milestone

          No milestone

          Relationships

          None yet

          Development

          No branches or pull requests

          Issue actions

          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
          Skip to content

          [FR] # MCP Security and Dynamic Client Registration #517

          Description

          @chussenot-believe

          MCP Security and Dynamic Client Registration

          Description

          We appreciate using SourceBot EE for its integration with LLMs and advanced code search capabilities. However, we have several security concerns around the current MCP server implementation that increase the risk of unauthorized data access, exfiltration, and could lead to supply chain compromission.

          Note: SourceBot already provides audit logs (see docs), but we request enhanced coverage for MCP-specific events and alerting hooks.

          Context and Security Concerns

          With the introduction of the MCP Server, SourceBot exposes a set of tools (search_code, list_repos, get_file_source) that are extremely powerful but also carry significant security implications:

          • Uncontrolled third parties - if the MCP server relays extracts (contexts, diffs, enriched prompts) to a remote LLM platform (SaaS, vendor LLM, etc.), it is possible that all or part of the code/documentation/secrets may pass through an uncontrolled third party.
          • Sensitive data exfiltration – attackers can use search_code to locate secrets (e.g., passwords, API tokens, private keys) and then retrieve them with get_file_source.
          • Uncontrolled discoverylist_repos makes it easy to enumerate all repositories and target sensitive ones.
          • Prompt injection / confused-deputy attacks – instructions hidden in indexed files could trick an agent into exfiltrating data through MCP tools.
          • Audit coverage – while audit logs exist, they should be extended with finer-grained MCP actions (tool usage, suspicious query detection) and integrated with alerting.
          • Supply chain exposure – use of unpinned npm execution in the mcp.json configuration (e.g., npx -y @sourcebot/mcp@latest) increases risk of package compromise.

          Proposed Solution: Hosted MCP API + Dynamic Client Registration

          Overview

          We propose implementing a hosted MCP API on SourceBot with Dynamic Client Registration support as defined in the MCP Authorization specification.

          Key Benefits

          1. No API Key Storage Required

            • Users don't need to store API keys locally
            • Eliminates risk of key leakage through configuration files
            • Reduces attack surface for credential theft
          2. Granular OAuth Schema Control

            • Administrators can precisely control which OAuth schemas are authorized
            • Better compliance with enterprise AI policies
            • Example: Allow vscode:// but block cursor:// based on security requirements
          3. Enhanced Security Model

            • OAuth-based authentication with proper scopes
            • Temporary access tokens with configurable expiration
            • Centralized revocation capabilities

          Technical Implementation

          1. Hosted MCP API

          • Deploy MCP server as a hosted service on SourceBot infrastructure
          • Provide secure endpoints for MCP tool access
          • Implement proper authentication and authorization layers

          2. Dynamic Client Registration

          3. Enterprise Policy Controls

          • Admin dashboard for OAuth schema management
          • Whitelist/blacklist specific client applications
          • Role-based access to different MCP tools
          • Audit logging for all MCP operations

          Requested Features

          1. Hosted MCP API

            • Deploy MCP server as a managed service
            • High availability and scalability
            • Secure communication channels
          2. Dynamic Client Registration Support

            • Implement MCP authorization specification
            • OAuth 2.0 integration
            • Client application management
          3. Enterprise Policy Controls

            • OAuth schema allowlist/denylist management
            • Granular tool access permissions
            • Repository and file-level access policies
          4. Query Controls

            • Built-in query filtering and result redaction for common secret patterns
            • Real-time content scanning and sanitization
            • Suspicious query detection and blocking
          5. Supply Chain Protections

            • Pin MCP client dependencies
            • Provide signed releases and/or official container images
            • Regular security updates and vulnerability scanning
          6. Enhanced Auditability & Alerting

            • Extend existing audit logs with detailed MCP tool usage events
            • Provide alerting hooks for suspicious activity
            • Integration with enterprise security tools

          Risks by Tool

          search_code

          What an attacker could do:

          • Run searches for secret patterns (password, token, key, BEGIN RSA PRIVATE KEY, etc.).
          • Extract code snippets and identify patterns in README files or commits to manipulate LLMs (prompt injection).
          • Use broad regex queries to map the entire codebase and find sensitive targets.

          Impact:

          • Rapid discovery of secrets, endpoints, and critical paths.
          • Foundation for follow-up attacks (SSRF, cloud account takeover).

          Mitigations with Hosted MCP + DCR:

          • OAuth scopes limit search capabilities per client
          • Server-side query validation and filtering
          • Automatic redaction of results containing common secret formats
          • Real-time monitoring and alerting on sensitive queries

          list_repos

          What an attacker could do:

          • Enumerate all indexed repositories.
          • Identify high-value repos by naming conventions (infra-, prod-, ci) and prioritize attacks.

          Impact:

          • Facilitates targeted attacks when combined with search_code and get_file_source.

          Mitigations with Hosted MCP + DCR:

          • OAuth scopes restrict repository listing permissions
          • Role-based access controls limit visible repositories
          • Admin policies can hide sensitive repository metadata

          get_file_source

          What an attacker could do:

          • Download critical files (CI/CD pipelines, configs, scripts, dumps, backups).
          • Extract credentials and historical secrets from old commits or configs.

          Impact:

          • Direct leakage of credentials, cloud compromise, CI/CD takeover, and loss of intellectual property.

          Mitigations with Hosted MCP + DCR:

          • OAuth scopes control file access permissions
          • Server-side redaction before returning results
          • File/repository allowlists enforced at the API level
          • Real-time content scanning and sanitization

          Implementation Roadmap

          Phase 1: Hosted MCP API

          • Deploy MCP server as managed service
          • Implement basic OAuth 2.0 authentication
          • Migrate existing API key users

          Phase 2: Dynamic Client Registration

          • Implement MCP authorization specification
          • Add client registration and management
          • Enable OAuth schema controls

          Phase 3: Enterprise Features

          • Advanced policy controls
          • Enhanced audit and monitoring
          • Integration with enterprise security tools

          Conclusion

          The MCP server in SourceBot must be treated as a high-risk surface. By implementing a hosted MCP API with Dynamic Client Registration, we can eliminate API key storage risks while providing administrators with precise control over client access and OAuth schemas. This approach enables secure deployment in sensitive environments while maintaining the powerful capabilities that make SourceBot valuable.


          Sources & References

          Some sources to read:

          Activity

          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

          Metadata

          Metadata

          Assignees

          No one assigned

            Labels

            Type

            No type

            Projects

            No projects

              Milestone

              No milestone

              Relationships

              None yet

              Development

              No branches or pull requests

              Issue actions

              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
              Skip to content

              [FR] # MCP Security and Dynamic Client Registration #517

              Description

              @chussenot-believe

              MCP Security and Dynamic Client Registration

              Description

              We appreciate using SourceBot EE for its integration with LLMs and advanced code search capabilities. However, we have several security concerns around the current MCP server implementation that increase the risk of unauthorized data access, exfiltration, and could lead to supply chain compromission.

              Note: SourceBot already provides audit logs (see docs), but we request enhanced coverage for MCP-specific events and alerting hooks.

              Context and Security Concerns

              With the introduction of the MCP Server, SourceBot exposes a set of tools (search_code, list_repos, get_file_source) that are extremely powerful but also carry significant security implications:

              • Uncontrolled third parties - if the MCP server relays extracts (contexts, diffs, enriched prompts) to a remote LLM platform (SaaS, vendor LLM, etc.), it is possible that all or part of the code/documentation/secrets may pass through an uncontrolled third party.
              • Sensitive data exfiltration – attackers can use search_code to locate secrets (e.g., passwords, API tokens, private keys) and then retrieve them with get_file_source.
              • Uncontrolled discoverylist_repos makes it easy to enumerate all repositories and target sensitive ones.
              • Prompt injection / confused-deputy attacks – instructions hidden in indexed files could trick an agent into exfiltrating data through MCP tools.
              • Audit coverage – while audit logs exist, they should be extended with finer-grained MCP actions (tool usage, suspicious query detection) and integrated with alerting.
              • Supply chain exposure – use of unpinned npm execution in the mcp.json configuration (e.g., npx -y @sourcebot/mcp@latest) increases risk of package compromise.

              Proposed Solution: Hosted MCP API + Dynamic Client Registration

              Overview

              We propose implementing a hosted MCP API on SourceBot with Dynamic Client Registration support as defined in the MCP Authorization specification.

              Key Benefits

              1. No API Key Storage Required

                • Users don't need to store API keys locally
                • Eliminates risk of key leakage through configuration files
                • Reduces attack surface for credential theft
              2. Granular OAuth Schema Control

                • Administrators can precisely control which OAuth schemas are authorized
                • Better compliance with enterprise AI policies
                • Example: Allow vscode:// but block cursor:// based on security requirements
              3. Enhanced Security Model

                • OAuth-based authentication with proper scopes
                • Temporary access tokens with configurable expiration
                • Centralized revocation capabilities

              Technical Implementation

              1. Hosted MCP API

              • Deploy MCP server as a hosted service on SourceBot infrastructure
              • Provide secure endpoints for MCP tool access
              • Implement proper authentication and authorization layers

              2. Dynamic Client Registration

              3. Enterprise Policy Controls

              • Admin dashboard for OAuth schema management
              • Whitelist/blacklist specific client applications
              • Role-based access to different MCP tools
              • Audit logging for all MCP operations

              Requested Features

              1. Hosted MCP API

                • Deploy MCP server as a managed service
                • High availability and scalability
                • Secure communication channels
              2. Dynamic Client Registration Support

                • Implement MCP authorization specification
                • OAuth 2.0 integration
                • Client application management
              3. Enterprise Policy Controls

                • OAuth schema allowlist/denylist management
                • Granular tool access permissions
                • Repository and file-level access policies
              4. Query Controls

                • Built-in query filtering and result redaction for common secret patterns
                • Real-time content scanning and sanitization
                • Suspicious query detection and blocking
              5. Supply Chain Protections

                • Pin MCP client dependencies
                • Provide signed releases and/or official container images
                • Regular security updates and vulnerability scanning
              6. Enhanced Auditability & Alerting

                • Extend existing audit logs with detailed MCP tool usage events
                • Provide alerting hooks for suspicious activity
                • Integration with enterprise security tools

              Risks by Tool

              search_code

              What an attacker could do:

              • Run searches for secret patterns (password, token, key, BEGIN RSA PRIVATE KEY, etc.).
              • Extract code snippets and identify patterns in README files or commits to manipulate LLMs (prompt injection).
              • Use broad regex queries to map the entire codebase and find sensitive targets.

              Impact:

              • Rapid discovery of secrets, endpoints, and critical paths.
              • Foundation for follow-up attacks (SSRF, cloud account takeover).

              Mitigations with Hosted MCP + DCR:

              • OAuth scopes limit search capabilities per client
              • Server-side query validation and filtering
              • Automatic redaction of results containing common secret formats
              • Real-time monitoring and alerting on sensitive queries

              list_repos

              What an attacker could do:

              • Enumerate all indexed repositories.
              • Identify high-value repos by naming conventions (infra-, prod-, ci) and prioritize attacks.

              Impact:

              • Facilitates targeted attacks when combined with search_code and get_file_source.

              Mitigations with Hosted MCP + DCR:

              • OAuth scopes restrict repository listing permissions
              • Role-based access controls limit visible repositories
              • Admin policies can hide sensitive repository metadata

              get_file_source

              What an attacker could do:

              • Download critical files (CI/CD pipelines, configs, scripts, dumps, backups).
              • Extract credentials and historical secrets from old commits or configs.

              Impact:

              • Direct leakage of credentials, cloud compromise, CI/CD takeover, and loss of intellectual property.

              Mitigations with Hosted MCP + DCR:

              • OAuth scopes control file access permissions
              • Server-side redaction before returning results
              • File/repository allowlists enforced at the API level
              • Real-time content scanning and sanitization

              Implementation Roadmap

              Phase 1: Hosted MCP API

              • Deploy MCP server as managed service
              • Implement basic OAuth 2.0 authentication
              • Migrate existing API key users

              Phase 2: Dynamic Client Registration

              • Implement MCP authorization specification
              • Add client registration and management
              • Enable OAuth schema controls

              Phase 3: Enterprise Features

              • Advanced policy controls
              • Enhanced audit and monitoring
              • Integration with enterprise security tools

              Conclusion

              The MCP server in SourceBot must be treated as a high-risk surface. By implementing a hosted MCP API with Dynamic Client Registration, we can eliminate API key storage risks while providing administrators with precise control over client access and OAuth schemas. This approach enables secure deployment in sensitive environments while maintaining the powerful capabilities that make SourceBot valuable.


              Sources & References

              Some sources to read:

              Activity

              Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

              Metadata

              Metadata

              Assignees

              No one assigned

                Labels

                Type

                No type

                Projects

                No projects

                  Milestone

                  No milestone

                  Relationships

                  None yet

                  Development

                  No branches or pull requests

                  Issue actions

                  , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
                  Skip to content

                  [FR] # MCP Security and Dynamic Client Registration #517

                  Description

                  @chussenot-believe

                  MCP Security and Dynamic Client Registration

                  Description

                  We appreciate using SourceBot EE for its integration with LLMs and advanced code search capabilities. However, we have several security concerns around the current MCP server implementation that increase the risk of unauthorized data access, exfiltration, and could lead to supply chain compromission.

                  Note: SourceBot already provides audit logs (see docs), but we request enhanced coverage for MCP-specific events and alerting hooks.

                  Context and Security Concerns

                  With the introduction of the MCP Server, SourceBot exposes a set of tools (search_code, list_repos, get_file_source) that are extremely powerful but also carry significant security implications:

                  • Uncontrolled third parties - if the MCP server relays extracts (contexts, diffs, enriched prompts) to a remote LLM platform (SaaS, vendor LLM, etc.), it is possible that all or part of the code/documentation/secrets may pass through an uncontrolled third party.
                  • Sensitive data exfiltration – attackers can use search_code to locate secrets (e.g., passwords, API tokens, private keys) and then retrieve them with get_file_source.
                  • Uncontrolled discoverylist_repos makes it easy to enumerate all repositories and target sensitive ones.
                  • Prompt injection / confused-deputy attacks – instructions hidden in indexed files could trick an agent into exfiltrating data through MCP tools.
                  • Audit coverage – while audit logs exist, they should be extended with finer-grained MCP actions (tool usage, suspicious query detection) and integrated with alerting.
                  • Supply chain exposure – use of unpinned npm execution in the mcp.json configuration (e.g., npx -y @sourcebot/mcp@latest) increases risk of package compromise.

                  Proposed Solution: Hosted MCP API + Dynamic Client Registration

                  Overview

                  We propose implementing a hosted MCP API on SourceBot with Dynamic Client Registration support as defined in the MCP Authorization specification.

                  Key Benefits

                  1. No API Key Storage Required

                    • Users don't need to store API keys locally
                    • Eliminates risk of key leakage through configuration files
                    • Reduces attack surface for credential theft
                  2. Granular OAuth Schema Control

                    • Administrators can precisely control which OAuth schemas are authorized
                    • Better compliance with enterprise AI policies
                    • Example: Allow vscode:// but block cursor:// based on security requirements
                  3. Enhanced Security Model

                    • OAuth-based authentication with proper scopes
                    • Temporary access tokens with configurable expiration
                    • Centralized revocation capabilities

                  Technical Implementation

                  1. Hosted MCP API

                  • Deploy MCP server as a hosted service on SourceBot infrastructure
                  • Provide secure endpoints for MCP tool access
                  • Implement proper authentication and authorization layers

                  2. Dynamic Client Registration

                  3. Enterprise Policy Controls

                  • Admin dashboard for OAuth schema management
                  • Whitelist/blacklist specific client applications
                  • Role-based access to different MCP tools
                  • Audit logging for all MCP operations

                  Requested Features

                  1. Hosted MCP API

                    • Deploy MCP server as a managed service
                    • High availability and scalability
                    • Secure communication channels
                  2. Dynamic Client Registration Support

                    • Implement MCP authorization specification
                    • OAuth 2.0 integration
                    • Client application management
                  3. Enterprise Policy Controls

                    • OAuth schema allowlist/denylist management
                    • Granular tool access permissions
                    • Repository and file-level access policies
                  4. Query Controls

                    • Built-in query filtering and result redaction for common secret patterns
                    • Real-time content scanning and sanitization
                    • Suspicious query detection and blocking
                  5. Supply Chain Protections

                    • Pin MCP client dependencies
                    • Provide signed releases and/or official container images
                    • Regular security updates and vulnerability scanning
                  6. Enhanced Auditability & Alerting

                    • Extend existing audit logs with detailed MCP tool usage events
                    • Provide alerting hooks for suspicious activity
                    • Integration with enterprise security tools

                  Risks by Tool

                  search_code

                  What an attacker could do:

                  • Run searches for secret patterns (password, token, key, BEGIN RSA PRIVATE KEY, etc.).
                  • Extract code snippets and identify patterns in README files or commits to manipulate LLMs (prompt injection).
                  • Use broad regex queries to map the entire codebase and find sensitive targets.

                  Impact:

                  • Rapid discovery of secrets, endpoints, and critical paths.
                  • Foundation for follow-up attacks (SSRF, cloud account takeover).

                  Mitigations with Hosted MCP + DCR:

                  • OAuth scopes limit search capabilities per client
                  • Server-side query validation and filtering
                  • Automatic redaction of results containing common secret formats
                  • Real-time monitoring and alerting on sensitive queries

                  list_repos

                  What an attacker could do:

                  • Enumerate all indexed repositories.
                  • Identify high-value repos by naming conventions (infra-, prod-, ci) and prioritize attacks.

                  Impact:

                  • Facilitates targeted attacks when combined with search_code and get_file_source.

                  Mitigations with Hosted MCP + DCR:

                  • OAuth scopes restrict repository listing permissions
                  • Role-based access controls limit visible repositories
                  • Admin policies can hide sensitive repository metadata

                  get_file_source

                  What an attacker could do:

                  • Download critical files (CI/CD pipelines, configs, scripts, dumps, backups).
                  • Extract credentials and historical secrets from old commits or configs.

                  Impact:

                  • Direct leakage of credentials, cloud compromise, CI/CD takeover, and loss of intellectual property.

                  Mitigations with Hosted MCP + DCR:

                  • OAuth scopes control file access permissions
                  • Server-side redaction before returning results
                  • File/repository allowlists enforced at the API level
                  • Real-time content scanning and sanitization

                  Implementation Roadmap

                  Phase 1: Hosted MCP API

                  • Deploy MCP server as managed service
                  • Implement basic OAuth 2.0 authentication
                  • Migrate existing API key users

                  Phase 2: Dynamic Client Registration

                  • Implement MCP authorization specification
                  • Add client registration and management
                  • Enable OAuth schema controls

                  Phase 3: Enterprise Features

                  • Advanced policy controls
                  • Enhanced audit and monitoring
                  • Integration with enterprise security tools

                  Conclusion

                  The MCP server in SourceBot must be treated as a high-risk surface. By implementing a hosted MCP API with Dynamic Client Registration, we can eliminate API key storage risks while providing administrators with precise control over client access and OAuth schemas. This approach enables secure deployment in sensitive environments while maintaining the powerful capabilities that make SourceBot valuable.


                  Sources & References

                  Some sources to read:

                  Activity

                  Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                  Metadata

                  Metadata

                  Assignees

                  No one assigned

                    Labels

                    Type

                    No type

                    Projects

                    No projects

                      Milestone

                      No milestone

                      Relationships

                      None yet

                      Development

                      No branches or pull requests

                      Issue actions

                      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                      Skip to content

                      [FR] # MCP Security and Dynamic Client Registration #517

                      Description

                      @chussenot-believe

                      MCP Security and Dynamic Client Registration

                      Description

                      We appreciate using SourceBot EE for its integration with LLMs and advanced code search capabilities. However, we have several security concerns around the current MCP server implementation that increase the risk of unauthorized data access, exfiltration, and could lead to supply chain compromission.

                      Note: SourceBot already provides audit logs (see docs), but we request enhanced coverage for MCP-specific events and alerting hooks.

                      Context and Security Concerns

                      With the introduction of the MCP Server, SourceBot exposes a set of tools (search_code, list_repos, get_file_source) that are extremely powerful but also carry significant security implications:

                      • Uncontrolled third parties - if the MCP server relays extracts (contexts, diffs, enriched prompts) to a remote LLM platform (SaaS, vendor LLM, etc.), it is possible that all or part of the code/documentation/secrets may pass through an uncontrolled third party.
                      • Sensitive data exfiltration – attackers can use search_code to locate secrets (e.g., passwords, API tokens, private keys) and then retrieve them with get_file_source.
                      • Uncontrolled discoverylist_repos makes it easy to enumerate all repositories and target sensitive ones.
                      • Prompt injection / confused-deputy attacks – instructions hidden in indexed files could trick an agent into exfiltrating data through MCP tools.
                      • Audit coverage – while audit logs exist, they should be extended with finer-grained MCP actions (tool usage, suspicious query detection) and integrated with alerting.
                      • Supply chain exposure – use of unpinned npm execution in the mcp.json configuration (e.g., npx -y @sourcebot/mcp@latest) increases risk of package compromise.

                      Proposed Solution: Hosted MCP API + Dynamic Client Registration

                      Overview

                      We propose implementing a hosted MCP API on SourceBot with Dynamic Client Registration support as defined in the MCP Authorization specification.

                      Key Benefits

                      1. No API Key Storage Required

                        • Users don't need to store API keys locally
                        • Eliminates risk of key leakage through configuration files
                        • Reduces attack surface for credential theft
                      2. Granular OAuth Schema Control

                        • Administrators can precisely control which OAuth schemas are authorized
                        • Better compliance with enterprise AI policies
                        • Example: Allow vscode:// but block cursor:// based on security requirements
                      3. Enhanced Security Model

                        • OAuth-based authentication with proper scopes
                        • Temporary access tokens with configurable expiration
                        • Centralized revocation capabilities

                      Technical Implementation

                      1. Hosted MCP API

                      • Deploy MCP server as a hosted service on SourceBot infrastructure
                      • Provide secure endpoints for MCP tool access
                      • Implement proper authentication and authorization layers

                      2. Dynamic Client Registration

                      3. Enterprise Policy Controls

                      • Admin dashboard for OAuth schema management
                      • Whitelist/blacklist specific client applications
                      • Role-based access to different MCP tools
                      • Audit logging for all MCP operations

                      Requested Features

                      1. Hosted MCP API

                        • Deploy MCP server as a managed service
                        • High availability and scalability
                        • Secure communication channels
                      2. Dynamic Client Registration Support

                        • Implement MCP authorization specification
                        • OAuth 2.0 integration
                        • Client application management
                      3. Enterprise Policy Controls

                        • OAuth schema allowlist/denylist management
                        • Granular tool access permissions
                        • Repository and file-level access policies
                      4. Query Controls

                        • Built-in query filtering and result redaction for common secret patterns
                        • Real-time content scanning and sanitization
                        • Suspicious query detection and blocking
                      5. Supply Chain Protections

                        • Pin MCP client dependencies
                        • Provide signed releases and/or official container images
                        • Regular security updates and vulnerability scanning
                      6. Enhanced Auditability & Alerting

                        • Extend existing audit logs with detailed MCP tool usage events
                        • Provide alerting hooks for suspicious activity
                        • Integration with enterprise security tools

                      Risks by Tool

                      search_code

                      What an attacker could do:

                      • Run searches for secret patterns (password, token, key, BEGIN RSA PRIVATE KEY, etc.).
                      • Extract code snippets and identify patterns in README files or commits to manipulate LLMs (prompt injection).
                      • Use broad regex queries to map the entire codebase and find sensitive targets.

                      Impact:

                      • Rapid discovery of secrets, endpoints, and critical paths.
                      • Foundation for follow-up attacks (SSRF, cloud account takeover).

                      Mitigations with Hosted MCP + DCR:

                      • OAuth scopes limit search capabilities per client
                      • Server-side query validation and filtering
                      • Automatic redaction of results containing common secret formats
                      • Real-time monitoring and alerting on sensitive queries

                      list_repos

                      What an attacker could do:

                      • Enumerate all indexed repositories.
                      • Identify high-value repos by naming conventions (infra-, prod-, ci) and prioritize attacks.

                      Impact:

                      • Facilitates targeted attacks when combined with search_code and get_file_source.

                      Mitigations with Hosted MCP + DCR:

                      • OAuth scopes restrict repository listing permissions
                      • Role-based access controls limit visible repositories
                      • Admin policies can hide sensitive repository metadata

                      get_file_source

                      What an attacker could do:

                      • Download critical files (CI/CD pipelines, configs, scripts, dumps, backups).
                      • Extract credentials and historical secrets from old commits or configs.

                      Impact:

                      • Direct leakage of credentials, cloud compromise, CI/CD takeover, and loss of intellectual property.

                      Mitigations with Hosted MCP + DCR:

                      • OAuth scopes control file access permissions
                      • Server-side redaction before returning results
                      • File/repository allowlists enforced at the API level
                      • Real-time content scanning and sanitization

                      Implementation Roadmap

                      Phase 1: Hosted MCP API

                      • Deploy MCP server as managed service
                      • Implement basic OAuth 2.0 authentication
                      • Migrate existing API key users

                      Phase 2: Dynamic Client Registration

                      • Implement MCP authorization specification
                      • Add client registration and management
                      • Enable OAuth schema controls

                      Phase 3: Enterprise Features

                      • Advanced policy controls
                      • Enhanced audit and monitoring
                      • Integration with enterprise security tools

                      Conclusion

                      The MCP server in SourceBot must be treated as a high-risk surface. By implementing a hosted MCP API with Dynamic Client Registration, we can eliminate API key storage risks while providing administrators with precise control over client access and OAuth schemas. This approach enables secure deployment in sensitive environments while maintaining the powerful capabilities that make SourceBot valuable.


                      Sources & References

                      Some sources to read:

                      Activity

                      Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                      Metadata

                      Metadata

                      Assignees

                      No one assigned

                        Labels

                        Type

                        No type

                        Projects

                        No projects

                          Milestone

                          No milestone

                          Relationships

                          None yet

                          Development

                          No branches or pull requests

                          Issue actions

                          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                          Skip to content

                          [FR] # MCP Security and Dynamic Client Registration #517

                          Description

                          @chussenot-believe

                          MCP Security and Dynamic Client Registration

                          Description

                          We appreciate using SourceBot EE for its integration with LLMs and advanced code search capabilities. However, we have several security concerns around the current MCP server implementation that increase the risk of unauthorized data access, exfiltration, and could lead to supply chain compromission.

                          Note: SourceBot already provides audit logs (see docs), but we request enhanced coverage for MCP-specific events and alerting hooks.

                          Context and Security Concerns

                          With the introduction of the MCP Server, SourceBot exposes a set of tools (search_code, list_repos, get_file_source) that are extremely powerful but also carry significant security implications:

                          • Uncontrolled third parties - if the MCP server relays extracts (contexts, diffs, enriched prompts) to a remote LLM platform (SaaS, vendor LLM, etc.), it is possible that all or part of the code/documentation/secrets may pass through an uncontrolled third party.
                          • Sensitive data exfiltration – attackers can use search_code to locate secrets (e.g., passwords, API tokens, private keys) and then retrieve them with get_file_source.
                          • Uncontrolled discoverylist_repos makes it easy to enumerate all repositories and target sensitive ones.
                          • Prompt injection / confused-deputy attacks – instructions hidden in indexed files could trick an agent into exfiltrating data through MCP tools.
                          • Audit coverage – while audit logs exist, they should be extended with finer-grained MCP actions (tool usage, suspicious query detection) and integrated with alerting.
                          • Supply chain exposure – use of unpinned npm execution in the mcp.json configuration (e.g., npx -y @sourcebot/mcp@latest) increases risk of package compromise.

                          Proposed Solution: Hosted MCP API + Dynamic Client Registration

                          Overview

                          We propose implementing a hosted MCP API on SourceBot with Dynamic Client Registration support as defined in the MCP Authorization specification.

                          Key Benefits

                          1. No API Key Storage Required

                            • Users don't need to store API keys locally
                            • Eliminates risk of key leakage through configuration files
                            • Reduces attack surface for credential theft
                          2. Granular OAuth Schema Control

                            • Administrators can precisely control which OAuth schemas are authorized
                            • Better compliance with enterprise AI policies
                            • Example: Allow vscode:// but block cursor:// based on security requirements
                          3. Enhanced Security Model

                            • OAuth-based authentication with proper scopes
                            • Temporary access tokens with configurable expiration
                            • Centralized revocation capabilities

                          Technical Implementation

                          1. Hosted MCP API

                          • Deploy MCP server as a hosted service on SourceBot infrastructure
                          • Provide secure endpoints for MCP tool access
                          • Implement proper authentication and authorization layers

                          2. Dynamic Client Registration

                          3. Enterprise Policy Controls

                          • Admin dashboard for OAuth schema management
                          • Whitelist/blacklist specific client applications
                          • Role-based access to different MCP tools
                          • Audit logging for all MCP operations

                          Requested Features

                          1. Hosted MCP API

                            • Deploy MCP server as a managed service
                            • High availability and scalability
                            • Secure communication channels
                          2. Dynamic Client Registration Support

                            • Implement MCP authorization specification
                            • OAuth 2.0 integration
                            • Client application management
                          3. Enterprise Policy Controls

                            • OAuth schema allowlist/denylist management
                            • Granular tool access permissions
                            • Repository and file-level access policies
                          4. Query Controls

                            • Built-in query filtering and result redaction for common secret patterns
                            • Real-time content scanning and sanitization
                            • Suspicious query detection and blocking
                          5. Supply Chain Protections

                            • Pin MCP client dependencies
                            • Provide signed releases and/or official container images
                            • Regular security updates and vulnerability scanning
                          6. Enhanced Auditability & Alerting

                            • Extend existing audit logs with detailed MCP tool usage events
                            • Provide alerting hooks for suspicious activity
                            • Integration with enterprise security tools

                          Risks by Tool

                          search_code

                          What an attacker could do:

                          • Run searches for secret patterns (password, token, key, BEGIN RSA PRIVATE KEY, etc.).
                          • Extract code snippets and identify patterns in README files or commits to manipulate LLMs (prompt injection).
                          • Use broad regex queries to map the entire codebase and find sensitive targets.

                          Impact:

                          • Rapid discovery of secrets, endpoints, and critical paths.
                          • Foundation for follow-up attacks (SSRF, cloud account takeover).

                          Mitigations with Hosted MCP + DCR:

                          • OAuth scopes limit search capabilities per client
                          • Server-side query validation and filtering
                          • Automatic redaction of results containing common secret formats
                          • Real-time monitoring and alerting on sensitive queries

                          list_repos

                          What an attacker could do:

                          • Enumerate all indexed repositories.
                          • Identify high-value repos by naming conventions (infra-, prod-, ci) and prioritize attacks.

                          Impact:

                          • Facilitates targeted attacks when combined with search_code and get_file_source.

                          Mitigations with Hosted MCP + DCR:

                          • OAuth scopes restrict repository listing permissions
                          • Role-based access controls limit visible repositories
                          • Admin policies can hide sensitive repository metadata

                          get_file_source

                          What an attacker could do:

                          • Download critical files (CI/CD pipelines, configs, scripts, dumps, backups).
                          • Extract credentials and historical secrets from old commits or configs.

                          Impact:

                          • Direct leakage of credentials, cloud compromise, CI/CD takeover, and loss of intellectual property.

                          Mitigations with Hosted MCP + DCR:

                          • OAuth scopes control file access permissions
                          • Server-side redaction before returning results
                          • File/repository allowlists enforced at the API level
                          • Real-time content scanning and sanitization

                          Implementation Roadmap

                          Phase 1: Hosted MCP API

                          • Deploy MCP server as managed service
                          • Implement basic OAuth 2.0 authentication
                          • Migrate existing API key users

                          Phase 2: Dynamic Client Registration

                          • Implement MCP authorization specification
                          • Add client registration and management
                          • Enable OAuth schema controls

                          Phase 3: Enterprise Features

                          • Advanced policy controls
                          • Enhanced audit and monitoring
                          • Integration with enterprise security tools

                          Conclusion

                          The MCP server in SourceBot must be treated as a high-risk surface. By implementing a hosted MCP API with Dynamic Client Registration, we can eliminate API key storage risks while providing administrators with precise control over client access and OAuth schemas. This approach enables secure deployment in sensitive environments while maintaining the powerful capabilities that make SourceBot valuable.


                          Sources & References

                          Some sources to read:

                          Activity

                          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                          Metadata

                          Metadata

                          Assignees

                          No one assigned

                            Labels

                            Type

                            No type

                            Projects

                            No projects

                              Milestone

                              No milestone

                              Relationships

                              None yet

                              Development

                              No branches or pull requests

                              Issue actions

                              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
                              Skip to content

                              [FR] # MCP Security and Dynamic Client Registration #517

                              Description

                              @chussenot-believe

                              MCP Security and Dynamic Client Registration

                              Description

                              We appreciate using SourceBot EE for its integration with LLMs and advanced code search capabilities. However, we have several security concerns around the current MCP server implementation that increase the risk of unauthorized data access, exfiltration, and could lead to supply chain compromission.

                              Note: SourceBot already provides audit logs (see docs), but we request enhanced coverage for MCP-specific events and alerting hooks.

                              Context and Security Concerns

                              With the introduction of the MCP Server, SourceBot exposes a set of tools (search_code, list_repos, get_file_source) that are extremely powerful but also carry significant security implications:

                              • Uncontrolled third parties - if the MCP server relays extracts (contexts, diffs, enriched prompts) to a remote LLM platform (SaaS, vendor LLM, etc.), it is possible that all or part of the code/documentation/secrets may pass through an uncontrolled third party.
                              • Sensitive data exfiltration – attackers can use search_code to locate secrets (e.g., passwords, API tokens, private keys) and then retrieve them with get_file_source.
                              • Uncontrolled discoverylist_repos makes it easy to enumerate all repositories and target sensitive ones.
                              • Prompt injection / confused-deputy attacks – instructions hidden in indexed files could trick an agent into exfiltrating data through MCP tools.
                              • Audit coverage – while audit logs exist, they should be extended with finer-grained MCP actions (tool usage, suspicious query detection) and integrated with alerting.
                              • Supply chain exposure – use of unpinned npm execution in the mcp.json configuration (e.g., npx -y @sourcebot/mcp@latest) increases risk of package compromise.

                              Proposed Solution: Hosted MCP API + Dynamic Client Registration

                              Overview

                              We propose implementing a hosted MCP API on SourceBot with Dynamic Client Registration support as defined in the MCP Authorization specification.

                              Key Benefits

                              1. No API Key Storage Required

                                • Users don't need to store API keys locally
                                • Eliminates risk of key leakage through configuration files
                                • Reduces attack surface for credential theft
                              2. Granular OAuth Schema Control

                                • Administrators can precisely control which OAuth schemas are authorized
                                • Better compliance with enterprise AI policies
                                • Example: Allow vscode:// but block cursor:// based on security requirements
                              3. Enhanced Security Model

                                • OAuth-based authentication with proper scopes
                                • Temporary access tokens with configurable expiration
                                • Centralized revocation capabilities

                              Technical Implementation

                              1. Hosted MCP API

                              • Deploy MCP server as a hosted service on SourceBot infrastructure
                              • Provide secure endpoints for MCP tool access
                              • Implement proper authentication and authorization layers

                              2. Dynamic Client Registration

                              3. Enterprise Policy Controls

                              • Admin dashboard for OAuth schema management
                              • Whitelist/blacklist specific client applications
                              • Role-based access to different MCP tools
                              • Audit logging for all MCP operations

                              Requested Features

                              1. Hosted MCP API

                                • Deploy MCP server as a managed service
                                • High availability and scalability
                                • Secure communication channels
                              2. Dynamic Client Registration Support

                                • Implement MCP authorization specification
                                • OAuth 2.0 integration
                                • Client application management
                              3. Enterprise Policy Controls

                                • OAuth schema allowlist/denylist management
                                • Granular tool access permissions
                                • Repository and file-level access policies
                              4. Query Controls

                                • Built-in query filtering and result redaction for common secret patterns
                                • Real-time content scanning and sanitization
                                • Suspicious query detection and blocking
                              5. Supply Chain Protections

                                • Pin MCP client dependencies
                                • Provide signed releases and/or official container images
                                • Regular security updates and vulnerability scanning
                              6. Enhanced Auditability & Alerting

                                • Extend existing audit logs with detailed MCP tool usage events
                                • Provide alerting hooks for suspicious activity
                                • Integration with enterprise security tools

                              Risks by Tool

                              search_code

                              What an attacker could do:

                              • Run searches for secret patterns (password, token, key, BEGIN RSA PRIVATE KEY, etc.).
                              • Extract code snippets and identify patterns in README files or commits to manipulate LLMs (prompt injection).
                              • Use broad regex queries to map the entire codebase and find sensitive targets.

                              Impact:

                              • Rapid discovery of secrets, endpoints, and critical paths.
                              • Foundation for follow-up attacks (SSRF, cloud account takeover).

                              Mitigations with Hosted MCP + DCR:

                              • OAuth scopes limit search capabilities per client
                              • Server-side query validation and filtering
                              • Automatic redaction of results containing common secret formats
                              • Real-time monitoring and alerting on sensitive queries

                              list_repos

                              What an attacker could do:

                              • Enumerate all indexed repositories.
                              • Identify high-value repos by naming conventions (infra-, prod-, ci) and prioritize attacks.

                              Impact:

                              • Facilitates targeted attacks when combined with search_code and get_file_source.

                              Mitigations with Hosted MCP + DCR:

                              • OAuth scopes restrict repository listing permissions
                              • Role-based access controls limit visible repositories
                              • Admin policies can hide sensitive repository metadata

                              get_file_source

                              What an attacker could do:

                              • Download critical files (CI/CD pipelines, configs, scripts, dumps, backups).
                              • Extract credentials and historical secrets from old commits or configs.

                              Impact:

                              • Direct leakage of credentials, cloud compromise, CI/CD takeover, and loss of intellectual property.

                              Mitigations with Hosted MCP + DCR:

                              • OAuth scopes control file access permissions
                              • Server-side redaction before returning results
                              • File/repository allowlists enforced at the API level
                              • Real-time content scanning and sanitization

                              Implementation Roadmap

                              Phase 1: Hosted MCP API

                              • Deploy MCP server as managed service
                              • Implement basic OAuth 2.0 authentication
                              • Migrate existing API key users

                              Phase 2: Dynamic Client Registration

                              • Implement MCP authorization specification
                              • Add client registration and management
                              • Enable OAuth schema controls

                              Phase 3: Enterprise Features

                              • Advanced policy controls
                              • Enhanced audit and monitoring
                              • Integration with enterprise security tools

                              Conclusion

                              The MCP server in SourceBot must be treated as a high-risk surface. By implementing a hosted MCP API with Dynamic Client Registration, we can eliminate API key storage risks while providing administrators with precise control over client access and OAuth schemas. This approach enables secure deployment in sensitive environments while maintaining the powerful capabilities that make SourceBot valuable.


                              Sources & References

                              Some sources to read:

                              Activity

                              Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                              Metadata

                              Metadata

                              Assignees

                              No one assigned

                                Labels

                                Type

                                No type

                                Projects

                                No projects

                                  Milestone

                                  No milestone

                                  Relationships

                                  None yet

                                  Development

                                  No branches or pull requests

                                  Issue actions