Security fixes are provided for the latest published ToolFence release. Users should upgrade to the newest patch before reporting an issue that may already be fixed; older pre-1.0 minor lines do not receive parallel security maintenance unless a release notice explicitly says otherwise.
Please use the repository's private GitHub Security Advisory flow. Do not include exploit details, credentials, approval tokens, policy files containing sensitive paths, or audit records in a public issue.
Include the affected ToolFence and Node.js versions, operating system, MCP client/server pair, a minimal reproduction, and the expected versus observed policy decision. Redact all secrets and personal paths.
You should receive an acknowledgement within seven days. Publication and remediation timing depend on severity and the availability of a safe fix.
ToolFence mediates MCP calls that cross its stdio proxy. It does not sandbox the upstream server process or prevent that process from directly using its operating-system permissions. See the security boundary in README.md before deployment.
Compatibility claims follow the supported/experimental/unverified/unsupported vocabulary in conformance/matrix.json. Unverified or unsupported protocol revisions, transports, or combinations never expand permissions: policy decisions are deterministic for every protocol shape and unknown or ambiguous actions cannot inherit default: allow. If you hit an unexpected decision on a protocol revision or Host combination not listed as supported, report it with the ToolFence and Node.js versions, the MCP protocol revision, and the expected versus observed decision.