Don't report vulnerabilities in public issues, discussions, or PRs. Instead, open a private security advisory.
Include the affected version and steps to reproduce. We'll acknowledge your report and let you know when a fix ships. Fixes target the latest published version of @certinia/apex-log-mcp.
- The server runs locally, makes no network calls of its own, and needs no API keys.
apexlog_execute_anonymousruns Apex against real Salesforce orgs. Every call is authorized by the type of the org it targets: a production org, or one whose type cannot be read, needs--allow-production-orgsor a per-call confirmation.--no-apex-executionrefuses every call.