Tools send parameters the API ignores; fence untrusted text beside write tools; no unauthenticated HTTP transports #3
Labels
No labels
bug
documentation
enhancement
security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo-mcp#3
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Found in the 2026-09-15 audit of the plugin repositories. Good already: the server is read-only by default, writes need both
--writeand thewritescope, there are no delete tools, and redirects are not followed.1. Two read tools send query parameters the API ignores
server.py:69-72:search_postingssendsshortlisted/undecided, but the core's/listingstakes onlystate(defaultundecided). Asking for shortlisted postings returns the undecided ones.server.py:90-92:list_interviewssendsupcoming, but/interviewstakesstate(defaultupcoming), so past interviews can never be listed.tests/test_server.pyuses an in-memory fake that accepts any parameter, which is why this passed.Fix:
state=values.openapi.jsonsnapshot is fine) and fail on unknown parameters.page, or loop.2. Untrusted text reaches the model unmarked while write tools are loaded
_as_text(server.py:197-213) flattens records, including captured descriptions, timeline bodies and IMAP-sourced notes, with no delimiters.change_status(for example towithdrawn),add_noteandcreate_cover_letter_draftare registered alongside (:108-142).INSTRUCTIONS.Fix:
ToolAnnotations:readOnlyHinton reads,destructiveHintonchange_status, so clients ask before running them.--write=notes,reminders, so status changes can stay off.3. HTTP transports run with no authentication
__main__.py:37:--transport sse|streamable-httpruns withoutauthor transport security. Anyone who can reach the port gets the power of the owner's token.__main__.py:47always passesread_only=not options.write, soPOSTULO_MCP_READ_ONLY(client.py:44-46) does nothing.POSTULO_MCP_INSECUREturns TLS verification off (client.py:51) and is not documented.Fix:
127.0.0.1with DNS-rebinding protection.POSTULO_MCP_INSECUREwith a warning, or remove it.4. Version pin
As in the other plugin repositories,
__version__(0.1.0) does not matchpyproject.toml(0.3.0), and the core is pinned to amaincommit. Version from metadata, and pin to the release.