Skip to content

Security: thelad-dev/MCP-IBMiDocs

Security

SECURITY.md

Security policy

Language: English | Deutsch

Reporting issues

Open a private or public GitHub issue with:

  • package version
  • Data Pack version
  • operating system
  • reproduction steps
  • relevant logs without secrets

Scope

This project is a local documentary MCP. Useful security reports include:

  • unexpected command execution
  • reads outside the configured Data Pack
  • exposure of local paths or secrets
  • bypass of the anti-RDi runtime policy
  • dependency vulnerabilities
  • Data Pack corruption

Runtime policy

The public runtime must not require or query:

  • installed RDi
  • active Eclipse Help
  • private local Eclipse/RDi Help endpoints used only for bootstrap
  • local bootstrap endpoints

ibmi_docs_sync may query public IBM Docs only when explicitly enabled with IBMI_DOCS_ALLOW_NETWORK_SYNC=1.

There aren't any published security advisories