Skip to content

Security: DeeeFOX/oh-my-agent-search

Security

SECURITY.md

Security Policy

Public-Safe Defaults

This repository must not contain real:

  • secrets
  • credentials
  • tokens
  • cookies
  • session material
  • private endpoints
  • private proxy values
  • personal email addresses
  • local absolute paths
  • customer data

Use https://search.example.org for shared examples.

Search Privacy

Search queries can reveal project intent. Do not send private code, private issue text, internal hostnames, unreleased names, customer data, or local paths to SearXNG or any upstream search engine.

MCP Scope

Prefer local or user MCP scope for personal setup. Use project scope only when the committed .mcp.json is reviewed and safe for every collaborator.

Reporting

Open a GitHub security advisory or private maintainer contact path if available. Do not disclose real credentials or private endpoints in public issues.

There aren't any published security advisories