Skip to content

[Disclosure] Clarify tool API and MCP host-boundary guidance in VS Code docs #9758

Description

@wenshameng

This is an exploit-free disclosure for the VS Code AI tool / MCP documentation surface.

Summary
We reviewed the public tool API and MCP developer guidance together with the host boundary described in the docs and validated sink shape locally without contacting external services or using real secrets. The current docs can still be interpreted as exposing path-write, command-execution, and network-request sink paths unless the intended trust boundary is made explicit.

Requested follow-up

  • confirm whether the current permission and tool-routing behavior is intended,
  • tighten the public guidance around workspace, command, and network boundaries,
  • point reporters to a preferred security channel if a private follow-up would be more appropriate.

Metadata

Metadata

Assignees

Labels

doc-enhancementsuggested addition or improvement

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions