The following versions of ContextFork (IPSF) are actively maintained and supported with security updates:
| Version | Supported |
|---|---|
| 1.2.x (IPSF-1.2) | ✅ |
| < 1.2.0 | ❌ |
ContextFork implements a defense-in-depth security model to ensure autonomous coding agents and MCP clients cannot be coerced into unauthorized filesystem access, credential exfiltration, or context poisoning.
-
ZF-026 Allowed Roots Contract (Fail-Closed):
- Configured via the
CONTEXTFORK_ALLOWED_ROOTSenvironment variable (semicolon-delimited list of absolute paths). - Fail-Closed by Design: If any configured root violates security constraints (relative path, directory traversal
.., UNC network path, junction/symlink escape, drive rootC:\, or user home directory), the entire configuration is rejected. The server either safely falls back to the local repository root (if verified as a Git repo) or runs with an empty allowed roots list. - Access to any path outside the verified allowed roots triggers an immediate
PermissionError.
- Configured via the
-
ZF-024 Cross-Host Context Isolation:
- ContextFork prevents cross-client context leakage. Local IDE database queries (e.g. conversation summaries) are strictly isolated and never accessed unless an explicit host signal (
CONTEXTFORK_HOST="antigravity") is provided. - For clients like Claude Desktop and Cursor, title resolution defaults safely to the local repository directory name.
- ContextFork prevents cross-client context leakage. Local IDE database queries (e.g. conversation summaries) are strictly isolated and never accessed unless an explicit host signal (
-
ZF-021 Git Drift & Phantom State Verification:
- Context resumption (
resume_session_context) deterministically cross-checks the snapshot's recorded Git HEAD SHA against the current working tree HEAD. Divergence triggers prominent drift warnings to prevent applying stale decisions to altered codebases.
- Context resumption (
-
ZF-020 Input Sanitization & Lineage Provenance:
- All conversation titles, session IDs, and snapshot IDs are cleansed of control characters (
\r,\n,\t,\0). - Session IDs are constrained to 128 alphanumeric characters (
[A-Za-z0-9_-]). Malformed or oversized IDs are sanitized tonullto prevent SQL/JSON injection.
- All conversation titles, session IDs, and snapshot IDs are cleansed of control characters (
-
ZF-022 Markdown Sanitization Shield:
- Interactive agent skills avoid raw HTML execution elements (
<button onclick="...">). All agent interactions rely strictly on native client modals (ask_question) or standard Markdown links.
- Interactive agent skills avoid raw HTML execution elements (
-
ZF-008 Atomic State Updates:
- Metadata files are written via atomic temporary files with explicit
flush,os.fsync, and atomic replacement (os.replace) with exponential backoff retry to prevent state corruption during concurrent access.
- Metadata files are written via atomic temporary files with explicit
We take the security of ContextFork seriously. If you discover a vulnerability or potential security risk:
- Do NOT report security vulnerabilities via public GitHub issues.
- Report vulnerabilities confidentially through GitHub Privately Reported Security Advisories or contact the project maintainer via GitHub (@mrblackman).
- Please include:
- Description of the vulnerability.
- Steps to reproduce or proof-of-concept script.
- Potential impact and affected components (CLI, MCP Server, or Skill).
We appreciate responsible disclosure and will respond promptly to review and resolve reported issues.