AID-H-029
Very High
MCP & Tool Client Security Hardening
This is the closest direct fit. The exposed trust boundary is the MCP client or SDK path that launches local STDIO servers, stores configuration, and mediates permissions. Hardening here means treating server launch, local state, cached descriptors, and permission mediation as a privileged client-side security surface.