RoslynMcp is pre-1.0. Security fixes are applied to the latest release on the dev branch.
RoslynMcp runs as a local process with your user permissions. It does not sandbox filesystem access — any tool can read or write files your user account can access. Only run RoslynMcp with agents you trust, on projects you control.
See Issue #9 for the filesystem access boundary roadmap.
If you discover a security vulnerability, please report it responsibly:
- Do not open a public GitHub issue.
- Use GitHub's private vulnerability reporting. If that is unavailable, contact the maintainer privately via github.com/MadQ.
- Include steps to reproduce and any relevant details.
You should receive an acknowledgment within 48 hours. We will work with you to understand the scope and coordinate a fix before any public disclosure.