Report privately
For vulnerabilities in the open-source CLI or MCP server, open a private GitHub Security Advisory.
Alternatively, email [email protected] with
the subject [SECURITY] short description. Do not post vulnerabilities, private
evidence or credentials in a public issue.
Include enough to reproduce
- The affected version and commit, if known.
- The component or command involved.
- Minimal reproduction steps in a test environment you control.
- The impact observed and any suggested fix.
- Your preferred name or handle for credit, if you want it.
Scope and limits
Reports about the CLI, MCP server, scope enforcement, authentication handling, tool wrappers or stored evidence belong in the repository's security process. For a problem with this website, use the email channel and identify the URL.
Report defects in third-party tools and infrastructure to their maintainers. Do not perform destructive tests, denial-of-service, social engineering or access to someone else's data. The project does not offer a paid bounty program.
If you encounter private data or unexpected access, stop and contact the owner. This page is not blanket authorization to test arbitrary project-related hosts.
Response process
The repository's policy commits to acknowledgment within three business days, initial triage within seven business days and coordinated disclosure for confirmed vulnerabilities. Credit can be included in release notes on request.
Read the repository security policy
Security contact file
Machine-readable contact details are available at security.txt. A public contact file does not change the authorized scope of a test.