Skip to content

Security: ajhcs/healthcare-data-mcp

Security

SECURITY.md

Security Policy

Supported Scope

Security reports are welcome for:

  • Remote code execution, command injection, or unsafe subprocess usage
  • Data exfiltration or path traversal in cache/download handling
  • Server-side request forgery or unsafe proxying
  • Credential leakage in configuration templates, docs, or logs
  • Supply-chain risks in install or release automation

This project serves public data only. It should not be used to process PHI or other regulated patient data.

Reporting

Please do not open a public GitHub issue for a suspected security problem.

Report privately to: security@ajhcs.org

Include:

  • Affected file or server
  • Reproduction steps
  • Impact assessment
  • Suggested remediation if you have one

We will acknowledge receipt and work on a fix before public disclosure.

There aren't any published security advisories