Skip to content

Security: EliasOulkadi/shokunin

Security

SECURITY.md

Security Policy

Scope

  • Memory system (mcp-server.py, chroma-helper.py)
  • Install scripts (install.ps1, install.sh)
  • MCP server protocol implementation
  • Skill content (factual errors, broken references)
  • Out of scope: Configuration files with user-specific paths

Reporting vulnerabilities

If you find a security vulnerability (exposed API keys, credentials in the repo, etc.):

  1. Do not open a public issue
  2. Email elias@cyberian.online directly
  3. PGP Key: not yet available. For sensitive reports, request the key at the same email.
  4. Include a description of the issue and steps to reproduce

We will respond within 48 hours and work on a fix before public disclosure.

Responsible disclosure

We ask that you give us reasonable time to address any security issue before sharing it publicly.

There aren't any published security advisories