Skip to content

Security policy

Private vulnerability reporting is enabled for this repository. Report vulnerabilities through GitHub's private report form or email sharafutdinov.di.dev@outlook.com. Include the affected version and steps to reproduce. Do not include credentials or confidential model data. Keep undisclosed vulnerabilities out of public issues and Discussions.

The file channel uses operating system permissions. Limit channel directory access to trusted users. Responses can contain model paths and parameter values. See server privacy settings.

HTTP binds to loopback by default and authenticates every route except /health with a per-user token. Health reveals document name, Revit version, process ID and workstation read-only state. Protect %LOCALAPPDATA%\RevitModelMcp\settings.json and use an encrypted tunnel for remote access. The listener has no built-in TLS. Actions require the workstation gate; the Python server also requires an explicit registration flag. See transport for bind settings and actions for the gates.

0.x releases are previews; report against the latest release or main.