main
fix: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure
Implement security enhancements for COMMAND_RESULTS handling to prevent session squatting and unauthorized result submissions
Implement task name sanitization and validation to prevent path traversal vulnerabilities
Add authorization checks for DEVICE_INFO_REQUEST to prevent cross-device disclosure