-
Notifications
You must be signed in to change notification settings - Fork 603
Pull requests: IBM/mcp-context-forge
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
feat(encoded-exfil): test, harden, and document encoded exfiltration detection plugin
COULD
P3: Nice-to-have features with minimal impact if left out; included if time permits
enhancement
New feature or request
plugins
security
Improves security
chore: add uv exclude-newer policy
chore
Linting, formatting, dependency hygiene, or project maintenance chores
devops
DevOps activities (containers, automation, deployment, makefiles, etc)
SHOULD
P2: Important but not vital; high-value items that are not crucial for the immediate release
feat: integrate Langfuse LLM observability via OTEL
#3900
opened Mar 28, 2026 by
crivetimihai
Loading…
9 tasks done
fix: use parameterized query in cleanup_old_results (CWE-89)
#3899
opened Mar 27, 2026 by
spidershield-contrib
Loading…
Draft plugins.md changes for tracking plan changes
documentation
Improvements or additions to documentation
WOULD
P4: Not a priority for current scope; very likely to move to future releases
feat: add Redis Cluster support via REDIS_CLUSTER_MODE setting
enhancement
New feature or request
performance
Performance related items
SHOULD
P2: Important but not vital; high-value items that are not crucial for the immediate release
feat(auth): add token time restriction validation
COULD
P3: Nice-to-have features with minimal impact if left out; included if time permits
enhancement
New feature or request
rbac
Role-based Access Control
security
Improves security
fix(auth): eliminate duplicate DB sessions in auth and RBAC middleware
bug
Something isn't working
MUST
P1: Non-negotiable, critical requirements without which the product is non-functional or unsafe
performance
Performance related items
fix(ui): remove duplicate disabled badge and tag/hook truncation on plugin cards
bug
Something isn't working
plugins
SHOULD
P2: Important but not vital; high-value items that are not crucial for the immediate release
ui
User Interface
feat(rbac): add tools.execute permission to team-scoped viewer role
enhancement
New feature or request
rbac
Role-based Access Control
security
Improves security
SHOULD
P2: Important but not vital; high-value items that are not crucial for the immediate release
refactor: standardize root_path access to settings.app_root_path
chore
Linting, formatting, dependency hygiene, or project maintenance chores
SHOULD
P2: Important but not vital; high-value items that are not crucial for the immediate release
chore(ci): remove unused linting-security-trufflehog make target
chore
Linting, formatting, dependency hygiene, or project maintenance chores
release-fix
Critical bugfix required for the release
SHOULD
P2: Important but not vital; high-value items that are not crucial for the immediate release
fix[bug]: handle non-JSON responses and query params in REST tools (#3855, #3857)
bug
Something isn't working
SHOULD
P2: Important but not vital; high-value items that are not crucial for the immediate release
feat(observability): add OTEL root and client spans for MCP flows
enhancement
New feature or request
observability
Observability, logging, monitoring
SHOULD
P2: Important but not vital; high-value items that are not crucial for the immediate release
feat: add MiniMax as first-class LLM provider
COULD
P3: Nice-to-have features with minimal impact if left out; included if time permits
enhancement
New feature or request
fix(docs): improve demo a2a agent docs
a2a
Support for A2A protocol
agents
Agent Samples
documentation
Improvements or additions to documentation
SHOULD
P2: Important but not vital; high-value items that are not crucial for the immediate release
feat(security): add MIME type restrictions for resources (US-2)
enhancement
New feature or request
security
Improves security
SHOULD
P2: Important but not vital; high-value items that are not crucial for the immediate release
feat(plugin): add tool call anomaly detection plugin
COULD
P3: Nice-to-have features with minimal impact if left out; included if time permits
enhancement
New feature or request
plugins
security
Improves security
feat(plugin): output length guard plugin
MUST
P1: Non-negotiable, critical requirements without which the product is non-functional or unsafe
plugins
release-fix
Critical bugfix required for the release
wxo
wxo integration
feat(discovery): add automatic tool discovery with hot/cold classification
COULD
P3: Nice-to-have features with minimal impact if left out; included if time permits
enhancement
New feature or request
release-fix
Critical bugfix required for the release
wxo
wxo integration
feat(api): expand /health API to include database and Redis status
api
REST API Related item
COULD
P3: Nice-to-have features with minimal impact if left out; included if time permits
enhancement
New feature or request
Use config.default_mask_strategy instead of hardcoded values
bug
Something isn't working
plugins
SHOULD
P2: Important but not vital; high-value items that are not crucial for the immediate release
fix(auth): close auth bypass on /mcp/{server_id} virtual server endpoints
release-fix
Critical bugfix required for the release
feat(ui): add admin UI for RBAC/ABAC policy engine
COULD
P3: Nice-to-have features with minimal impact if left out; included if time permits
enhancement
New feature or request
rbac
Role-based Access Control
ui
User Interface
feat(rate-limiter): pluggable algorithms with Rust-backed execution engine, benchmarks, and validation
enhancement
New feature or request
MUST
P1: Non-negotiable, critical requirements without which the product is non-functional or unsafe
performance
Performance related items
plugins
release-fix
Critical bugfix required for the release
wxo
wxo integration
Previous Next
ProTip!
Mix and match filters to narrow down what you’re looking for.