GridTwin is an experimental hackathon proof of concept. Security fixes are applied to the latest commit on main and the public deployment at gridtwin.vercel.app.
Please do not disclose security vulnerabilities in a public issue. Use GitHub's private Report a vulnerability flow and include:
- the affected URL, component, or WebMCP tool;
- steps to reproduce;
- the expected and observed behavior; and
- any suggested mitigation.
GridTwin is client-only and intentionally has no accounts, API keys, backend, or long-term data store. Reports concerning WebMCP trust boundaries, tool input validation, browser state recovery, or unintended authority escalation are especially valuable.
The energy model uses synthetic data and produces indicative planning estimates. It is not engineering, investment, safety, or operational advice.