Skip to content

Security: nubiia-dev/mcp-holded

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.x.x

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it responsibly:

  1. Do not open a public issue
  2. Email the maintainer directly or use GitHub's private vulnerability reporting
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

We will respond within 48 hours and work with you to understand and address the issue.

Security Best Practices

When using this MCP server:

  • Keep your Holded API key secure and never commit it to version control
  • Use environment variables for sensitive configuration
  • Regularly update to the latest version for security patches
  • Review the permissions granted to the MCP server in your AI assistant

There aren't any published security advisories