Skip to content

MCP Safety Notes ​

Prompt injection is an open problem for tool-using agents. A downloaded model's description, a README inside an archive, 3MF metadata, or a web page can all contain instructions aimed at your agent. Practical mitigations:

  • Treat tool output and downloaded files as untrusted input.
  • Keep printer keys and access codes in server configuration, with the least privilege your printer software allows.
  • Keep per-call executable selectors off. Slicer, bridge, and Blender commands come from server configuration unless MCP_ALLOW_EXECUTABLE_ARG=1 is set.
  • Keep print confirmation on. The server asks a human through MCP elicitation before every print start and positive heating command, and refuses clients that cannot ask. PRINT_REQUIRE_CONFIRMATION=0 (all printers) or BAMBU_REQUIRE_CONFIRMATION=0 (Bambu only) opts out for headless setups; the first print after a finished job still asks.
  • Heater ceilings come only from server configuration (PRINTER_MAX_NOZZLE_TEMP, PRINTER_MAX_BED_TEMP, PRINTER_MAX_CHAMBER_TEMP, or Bambu's per-model limits). Tool arguments and G-code never raise them.
  • Run the streamable HTTP transport on a trusted network. It binds to 127.0.0.1 by default and has no built-in authentication.
  • Set BAMBU_MODEL correctly and never substitute a similar model.

Released under the GPL-2.0 license. An independent open-source project, not affiliated with any printer manufacturer or host software.