Skip to content

Security: gensecaihq/mcpscc

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in MSCC, please report it responsibly.

Do NOT create a public GitHub issue for security vulnerabilities.

How to Report

  1. Email security concerns to the maintainers
  2. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial Assessment: Within 7 days
  • Resolution: Depends on severity

Supported Versions

Version Supported
0.1.x

Security Best Practices

When using MSCC:

  1. Keep Updated: Use the latest version
  2. API Security: Use API keys in production
  3. Network: Run API server behind a reverse proxy
  4. Secrets: Never commit .env files
  5. Permissions: Run with minimal required permissions

Known Limitations

  • Static analysis has false positives/negatives
  • Pattern matching cannot catch all vulnerabilities
  • Not a replacement for comprehensive security audits

There aren’t any published security advisories