Please use Security → Report a vulnerability on this GitHub repository. That opens a private security advisory with the maintainer. Do not put API keys, OAuth tokens, passwords, workout data, or other personal information in a public issue.
Include a concise impact statement, reproduction steps, and the affected plugin version. Sanitized logs are welcome; credentials are not.
This policy covers the plugin manifests, skill instructions, documentation,
and original assets in this repository. Vulnerabilities in Hevy, ChatGPT,
Codex, or the third-party hevy-mcp service should be reported to the
respective project owner.
This repository never requires a Hevy API key in a file, prompt, URL, Git commit, screenshot, or issue. Enter the key only on the hosted OAuth authorization page. If a key is exposed, revoke or rotate it in Hevy before continuing.