Please do not disclose security vulnerabilities in public issues.
Use GitHub's private vulnerability reporting flow:
https://github.com/aakcay5656/devtools-lens-mcp/security/advisories/new
Include the affected version, reproduction steps, expected impact, and any suggested mitigation. You should receive an initial response within seven days.
DevTools Lens MCP controls a browser with powerful debugging privileges. Never connect it to a trusted personal browser profile or expose a Chromium remote-debugging port publicly. Localhost and private-network navigation are allowed intentionally for frontend development; isolate the server when inspecting untrusted pages.