MCP Safety Notes
Prompt injection is an open problem for tool-using agents. A downloaded model's description, a README inside an archive, 3MF metadata, or a web page can all contain instructions aimed at your agent. Practical mitigations:
- Treat tool output and downloaded files as untrusted input.
- Keep printer keys and access codes in server configuration, with the least privilege your printer software allows.
- Keep per-call executable selectors off. Slicer, bridge, and Blender commands come from server configuration unless
MCP_ALLOW_EXECUTABLE_ARG=1is set. - Keep print confirmation on. The server asks a human through MCP elicitation before every print start and positive heating command, and refuses clients that cannot ask.
PRINT_REQUIRE_CONFIRMATION=0(all printers) orBAMBU_REQUIRE_CONFIRMATION=0(Bambu only) opts out for headless setups; the first print after a finished job still asks. - Heater ceilings come only from server configuration (
PRINTER_MAX_NOZZLE_TEMP,PRINTER_MAX_BED_TEMP,PRINTER_MAX_CHAMBER_TEMP, or Bambu's per-model limits). Tool arguments and G-code never raise them. - Run the streamable HTTP transport on a trusted network. It binds to
127.0.0.1by default and has no built-in authentication. - Set
BAMBU_MODELcorrectly and never substitute a similar model.