| Version | Supported |
|---|---|
| 0.1.x | ✅ |
| < 0.1 | ❌ |
Do not open a public GitHub issue for security vulnerabilities.
Report privately using one of these:
- GitHub Security Advisories (preferred)
- Contact the maintainer through their GitHub profile
- Description of the vulnerability
- Steps to reproduce
- Affected versions
- Potential impact (e.g. credential leak, arbitrary code execution)
- Suggested fix or mitigation, if you have one
| Step | Target |
|---|---|
| Acknowledgement | 72 hours |
| Status update | 7 days |
| Fix or mitigation | Best effort |
In scope:
- The
tooltrimnpm package and CLI - This repository's source code
- Default configuration and documented deployment patterns
Out of scope:
- Vulnerabilities in upstream MCP servers you connect via config
- Misconfiguration of secrets in user-owned
tooltrim.config.yamlfiles - Issues in third-party dependencies (report those to the upstream project; we will bump deps when fixes are available)
Thank you for helping keep Tooltrim and its users safe.