Corsen Context guide
Security boundary
Published
Strict schemas, same-origin routing, rate limiting, and bounded output.
The boundary is strict input schemas with runtime validation, same-origin WebMCP resolution with frame refusal and no credentials, rate limiting before optional authentication, bounded request bodies and JSON depth, same-site URL checks, and generated-metadata escaping. Page bodies remain untrusted site-authored content.