Skip to content

mcp: bundled-id shadow defense (physical-access scenario) #383

@thinmintdev

Description

@thinmintdev

Surfaced by PR #368 reviewer. If root drops e.g. hal0-admin.toml in /etc/hal0/mcp-servers/, list_servers shows duplicate. Physical access only; document the scenario in security docs at minimum, or filter bundled-id .toml files in list_installed.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions