Do not disclose vulnerabilities, credentials, customer information, or exploitable details in a public issue.
Report security concerns privately through DepthFeed contact. Include the affected endpoint, impact, reproduction steps, and a safe way to contact you. We will acknowledge actionable reports and coordinate disclosure after a fix is available.
The MCP tools are read-only, but reports involving authentication, authorization, rate limits, data isolation, or unexpected tool access are especially useful.