Skip to content

Security: cicoub13/scribe-mcp

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Do not open a public issue for suspected security problems.

Instead, use GitHub private vulnerability reporting if it is enabled for the repository. If not, contact the repository owner directly and include:

  • A clear description of the issue
  • Reproduction steps
  • Impact assessment
  • Any suggested mitigation

Scope

This project handles local file access and third-party LLM API requests. Reports involving path handling, unintended file writes, prompt injection impact, credential exposure, and dependency risk are in scope.

Disclosure

Please allow time to investigate and ship a fix before public disclosure.

There aren't any published security advisories