Skip to content

Security: getbirthchart-com/getbirthchart-mcp

Security

SECURITY.md

Security

Reporting a vulnerability

Please do not open a public issue for a suspected vulnerability. Contact GetBirthChart through the private security contact published at getbirthchart.com/developers, including a concise description, affected version, reproduction steps, and impact. Never include a real API key or private birth data.

Credential handling

  • Configure credentials with GETBIRTHCHART_API_KEY.
  • Do not pass credentials as command-line arguments or MCP tool input.
  • The server never logs the key or sends it anywhere except the configured API base URL as an Authorization header managed by @getbirthchart/sdk.
  • Keep host configuration files containing keys outside source control.

Security boundaries

The server exposes only explicit calculation methods and fixed resources. Tool input cannot select an endpoint, URL, host, method, header, shell command, or proxy target. Birth inputs are not persisted or cached.

Supported versions

The latest published version is supported. Security fixes are released as new patch or minor versions under semantic versioning where possible. Runtime support is Node.js 20+.

There aren't any published security advisories