Skip to content

docs: credit the #13 and #14 security reports - #25

Merged
DMontgomery40 merged 1 commit into
mainfrom
docs/credit-security-reports
Sep 29, 2026
Merged

DMontgomery40 merged 1 commit into
mainfrom
docs/credit-security-reports

Conversation

@DMontgomery40

@DMontgomery40 DMontgomery40 commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Credits @BruceJqs (#14, per-call bridge_command executable selection, fixed by the #20/#21 opt-in gate) and @razashariff (#13, print-command authentication proposal; 1.2.10 answers the same threat with human confirmation and file inspection rather than signing) in CONTRIBUTORS.md. Docs only; the npm package does not ship CONTRIBUTORS.md.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Vfeu6oSQ6vQ6ykWEBMoYW2
@DMontgomery40
DMontgomery40 merged commit 7c6041c into main Sep 29, 2026
7 checks passed

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f0edbbb502

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread CONTRIBUTORS.md
| [Remco Veldkamp (remcoder)](https://github.com/remcoder) | Reports that a large OctoPrint file list (324 files, about 500 KB of JSON) overflows a model's context window in [#4](https://github.com/DMontgomery40/mcp-3D-printer-server/issues/4). The full list is still returned; this is documented as a limitation. |
| [Jose Martinez (josemartinezbli)](https://github.com/josemartinezbli) | Reports that `SLICER_PROFILE` was ambiguous for PrusaSlicer and OrcaSlicer, with slicer error output, in [#7](https://github.com/DMontgomery40/mcp-3D-printer-server/issues/7). The slicing guide now documents profiles per slicer. |
| [Gioele Molinari (gioelemo)](https://github.com/gioelemo) | Shares a Prusa Connect configuration in [#9](https://github.com/DMontgomery40/mcp-3D-printer-server/issues/9). The Prusa adapter now normalizes `connect.prusa3d.com` to HTTPS; cloud access has not been confirmed on hardware. |
| [BruceJin (BruceJqs)](https://github.com/BruceJqs) | Reports that a per-call `bridge_command` in `blender_mcp_edit_model` could launch an arbitrary local executable (CWE-78) in [#14](https://github.com/DMontgomery40/mcp-3D-printer-server/issues/14). Per-call executable selectors now require the server-side `MCP_ALLOW_EXECUTABLE_ARG=1` opt-in ([#20](https://github.com/DMontgomery40/mcp-3D-printer-server/pull/20), [#21](https://github.com/DMontgomery40/mcp-3D-printer-server/pull/21)). |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Bump the npm patch version for this documentation update

When this commit is integrated into main, both package manifests remain at 1.2.10, so the required npm publication cannot represent this update and attempting to republish the existing version will fail. Include the npm version patch changes to package.json and package-lock.json in this integration.

AGENTS.md reference: AGENTS.md:L7-L7

Useful? React with 👍 / 👎.

Comment thread CONTRIBUTORS.md

| Contributor | Contribution |
| --- | --- |
| [Raza Sharif (razashariff)](https://github.com/razashariff) | Proposes cryptographic signing, replay protection, and agent identity checks before print commands in [#13](https://github.com/DMontgomery40/mcp-3D-printer-server/issues/13). Signing is not implemented; since 1.2.10, every print start and positive heating command requires human confirmation through MCP elicitation, and printed files are inspected before dispatch. |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Qualify the claim that every print requires confirmation

In headless configurations with PRINT_REQUIRE_CONFIRMATION=0 (or BAMBU_REQUIRE_CONFIRMATION=0 for Bambu), requireHumanConfirmation() skips elicitation for ordinary print and heating commands, so saying that every command requires human confirmation overstates the mitigation attributed to 1.2.10. State that confirmation is required by default unless the server explicitly opts out; only physical checks such as finished-bed clearance remain mandatory after opt-out.

AGENTS.md reference: AGENTS.md:L37-L37

Useful? React with 👍 / 👎.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T07:52:12.823711Z f0edbbb PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant