Report plugin or Project Feed MCP security issues to security@projectfeed.app.
Include the affected component, the behavior you observed, and steps to reproduce it. Do not open a public issue for a vulnerability, API key, access token, or private workspace data.
The plugin repository contains no credentials. Users configure a dedicated Project Feed API key through their client settings or launch environment. Revoke that key in Project Feed if you believe it was exposed.