Skip to content

Security Policy

local-shell-mcp exposes shell, filesystem, remote-worker, and optional public HTTP surfaces.

Reporting vulnerabilities

Please report suspected vulnerabilities privately to the maintainers rather than opening a public issue with exploit details. Include the affected version or commit, deployment mode, impact, and a minimal redacted reproduction.

Supported line

Security fixes target the current main branch and latest released 3.x line unless otherwise noted.