Skip to content

Security review pilot for Context+'s write/execute tool surface #45

Description

@Ventrova

Hi, I maintain sentinel-scan-cli, an open-source OWASP-mapped security scanner for MCP servers. Discussions looks disabled on this repo so filing as an issue instead, feel free to close/relabel.

Specific note on Context+: propose_commit is described as "the only way to write code" and run_static_analysis executes native linters/compilers against the target codebase. That is a direct-write-plus-execute surface driven by LLM tool calls, which is exactly the kind of thing worth having an independent look at, especially since it also builds a persistent memory/RAG graph from the codebase that downstream calls can traverse.

I am piloting a $99 one-time scan (tool input validation, write-path safety, execution surface) with a short written report, optional $299/yr to re-run per release as a badge. Nothing to install on your side, I run it and send results.

Happy to just run it and send the report either way. Good luck with the project regardless.

Skye, Ventrova (ventrova.dev)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions