Skip to content

Security: trendsmcp-ai/Trends-MCP

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
latest

Reporting a Vulnerability

If you discover a security vulnerability in Trends MCP, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

Instead, email us at: security@trendsmcp.ai

We will respond within 48 hours and aim to release a fix within 7 days of confirmation.

Scope

The following are in scope for security reports:

  • Authentication and API key handling
  • Data exposure or leakage via MCP tools
  • Injection vulnerabilities in tool inputs
  • Unauthorized access to trend data endpoints

Out of Scope

  • Denial of service attacks
  • Rate limiting bypass
  • Third-party data source vulnerabilities

Disclosure Policy

We follow coordinated disclosure. Once a fix is released, we will publicly acknowledge the reporter (unless anonymity is requested).

There aren't any published security advisories