/** * Security utilities for MCP tool responses. * Wraps untrusted external content with safety markers to defend against * Indirect Prompt Injection (XPIA) attacks. */ /** * Tools that return content from external Notion sources (untrusted). * * `file_uploads` is included because its response includes attachment URLs, * filenames, and free-text metadata that can come from an untrusted upstream * Notion workspace. Treat that payload the same as `pages`/`blocks` content. */ export declare const EXTERNAL_CONTENT_TOOLS: Set; /** * Validates a URL to ensure it uses a safe protocol. * Prevents XSS attacks via javascript:, data:, vbscript:, etc. */ export declare function isSafeUrl(url: string): boolean; /** Wrap tool result with safety markers if it contains external content */ export declare function wrapToolResult(toolName: string, jsonText: string): string; /** * Validates a web URL for safe opening in external browsers. * Stricter than isSafeUrl: requires http/https and prevents shell flag injection. */ export declare function isSafeWebUrl(url: string): boolean; //# sourceMappingURL=security.d.ts.map