Skip to content

Security: VictorLee2035/singchat-claude-plugin

Security

SECURITY.md

Security policy

Please report suspected vulnerabilities privately to hello@singchat.org. Include the affected plugin version, reproduction steps, and impact. Do not include passwords, OAuth tokens, API keys, session cookies, customer messages, or other tenant data in a public GitHub issue.

The plugin stores no static SingChat credentials. Authentication is completed through the SingChat OAuth flow, and the remote MCP server enforces tenant and scope boundaries on every request.

For a lost device or unwanted connection, revoke the Claude connection from the SingChat MCP connections page.

There aren't any published security advisories