XTester MCP security and privacy

Transport and data

  • The MCP transport is local stdio.
  • XTester does not open a separate MCP network listener.
  • "Local stdio" describes only the client-to-host transport and does not guarantee an entirely local or offline AI workflow. The MCP client or provider may transmit and store tool names and schemas, arguments, results, strategy excerpts, paths, logs and market-data excerpts.
  • Review your AI client's retention and telemetry settings; do not send credentials or private strategy source; minimise output; use a local model/client when data must not leave the device.
  • A claim that "data never leaves the device" is not allowed without end-to-end verification of the specific client, provider and configuration.

Consent and actions

  • The user explicitly confirms install and launch of the application.
  • A read-only connection check runs first.
  • Before mutating actions the agent confirms the workspace/project identity.
  • Remote writes and updates are described as requiring confirmation; the site does not assert runtime enforcement without testing a specific client/host.
  • XTester telemetry is optional (opt-in) and is enabled only with the user's consent in the application. Do not send credentials, strategy source or sensitive data in telemetry/support reports.

Download