Skip to content

Security: ogradyliam5/hevy-chatgpt-plugin

SECURITY.md

Security

Reporting a vulnerability

Please use Security → Report a vulnerability on this GitHub repository. That opens a private security advisory with the maintainer. Do not put API keys, OAuth tokens, passwords, workout data, or other personal information in a public issue.

Include a concise impact statement, reproduction steps, and the affected plugin version. Sanitized logs are welcome; credentials are not.

Scope

This policy covers the plugin manifests, skill instructions, documentation, and original assets in this repository. Vulnerabilities in Hevy, ChatGPT, Codex, or the third-party hevy-mcp service should be reported to the respective project owner.

Credential handling

This repository never requires a Hevy API key in a file, prompt, URL, Git commit, screenshot, or issue. Enter the key only on the hosted OAuth authorization page. If a key is exposed, revoke or rotate it in Hevy before continuing.

There aren't any published security advisories