Under the hood
Env-var masking in allow and deny server displays now also covers a fallback env source.
The env-var scrubbing used when building deniedMcpServers and allowedMcpServers display lists now also redacts and normalizes a fallback env source (yxn().fallbackEnv) in addition to the primary env map, so MCP server commands and URLs shown for allow/deny rules stay masked regardless of which env the values came from.