Design-time MCP server that reads .knxproj (read-only), validates naming/DPT/status, and generates Home Assistant KNX YAML + ETS-importable group addresses (XML/CSV). No live bus access — confined-workspace writes only. Includes: 12 MCP tools, end-to-end smoke test, MIT license, English-first README (+ Russian), CONTRIBUTING with a real-project test call, SECURITY policy, CHANGELOG, GitHub Actions CI (Python 3.10–3.12), and issue/PR templates. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
1.4 KiB
Security Policy
The safety model
nickol-knx-mcp is a design-time tool with a deliberately small attack surface:
- No bus access. There is no KNX/IP or other networking/bus library in the dependency tree.
The server cannot reach a live KNX installation.
workspace_info()reportsbus_access: false. - Read-only on
.knxproj. Onlyproject.pyreads the project, and it never writes to it. - Confined writes. All generated files are constrained to the
NICKOL_KNX_WORKSPACEdirectory; writes outside it are rejected.
Handling project data
A .knxproj and an ETS keyring (.knxkeys) can contain sensitive information (topology, device
addresses, secure keys). This tool reads the project locally and writes only into your workspace —
nothing is uploaded anywhere. Do not commit real .knxproj / .knxkeys files to a public
repository; the provided .gitignore excludes them by default.
Reporting a vulnerability
If you find a security issue (e.g. a path-escape past the workspace confinement, or any way the server could touch a bus), please do not open a public issue. Instead use GitHub's private vulnerability reporting for this repository. We'll acknowledge within a reasonable time and coordinate a fix and disclosure.
Supported versions
This is a beta; security fixes target the latest main and the most recent release.