Crucible is pre-1.0. Fixes land on the latest released minor version only.
Please report security issues privately through GitHub Security Advisories rather than opening a public issue. Expect an initial response within a week.
Crucible reads files you point it at and renders SVG you supply. Two things are worth knowing:
- SVG rendering goes through resvg, which does not execute scripts or fetch remote resources. Treat untrusted SVG with the same care you would any untrusted input regardless.
- The MCP server speaks stdio to a local client and opens no network listener. It reads rubric and style-profile files from paths the caller provides, so the caller controls what it can reach.