If you discover a security vulnerability, please do not open a public issue.
Report privately via GitHub Security Advisories.
- The VS Code extension
- The MCP server bridge
- Local session log reading
- Privacy guarantees (token-only, no message content)
- The signalaf.com web app (report at sigrank-app)
- The sigrank CLI/MCP server (report at sigrank-mcp)
- Acknowledgement within 48 hours
- Assessment within 7 days