If you discover a security vulnerability, please report it responsibly:
- Do NOT open a public issue
- Email the maintainer directly or use GitHub's private vulnerability reporting
- API tokens and access credentials should only be stored in environment variables
- Never commit
.envfiles to version control - The MCP server communicates with the detection API over HTTPS