Security fixes are made on the latest released version.
Please use GitHub private vulnerability reporting. Do not open a public issue for a suspected vulnerability or include credentials, tokens, private MCP schemas, or production records in a report.
filter-mcp-tools narrows the tools visible and callable through its local relay.
Anyone who can change the relay command or configuration can change that filter,
so upstream authorization remains the actual access-control boundary.