| Version | Supported |
|---|---|
| 1.x.x | ✅ |
If you discover a security vulnerability in this project, please report it responsibly:
- Do not open a public issue
- Email the maintainer directly or use GitHub's private vulnerability reporting
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
We will respond within 48 hours and work with you to understand and address the issue.
When using this MCP server:
- Keep your Holded API key secure and never commit it to version control
- Use environment variables for sensitive configuration
- Regularly update to the latest version for security patches
- Review the permissions granted to the MCP server in your AI assistant