Skip to content

Add MCP Server security and sandbox documentation #62

@michaellwest

Description

@michaellwest

Scope

Document the three sandbox modes (read-only, filtered, unrestricted) with decision matrix:

  • AST-based script validation
  • Command allowlists/blocklists
  • Obfuscation detection
  • CLM auto-detection
  • Confirmation-required commands
  • Security recommendations per environment

Important: Clarify that sandbox/security modes only apply to remoting, not other SPE integration points (ISE, Console, etc.), and explain why these protections are needed for remoting specifically.

Cross-reference existing security/ pages and SitecorePowerShell/Console#1419 (CLM).

References

Files

  • New mcp-server/security.md
  • SUMMARY.md — Add under MCP Server

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions