Use GitHub's private vulnerability reporting for this repository. Do not open a public issue for a suspected vulnerability or include API keys, customer assets, account-specific IDs, private URLs, or unredacted API responses in an issue.
Include the affected version, a concise reproduction, the security impact, and any suggested remediation. You should receive an acknowledgment within seven days.
Security fixes are applied to the latest npm release. Update to the current version before reporting a problem that may already be fixed.
The server reads IMAGERELAY_API_KEY from its process environment. When IMAGERELAY_API_KEY_OP_REF is configured, the optional 1Password CLI fallback resolves that reference in memory and does not write the value to disk. Never commit credentials to an MCP client configuration or repository.