| Version | Supported |
|---|---|
| latest | ✅ |
If you discover a security vulnerability in Trends MCP, please report it responsibly.
Do not open a public GitHub issue for security vulnerabilities.
Instead, email us at: security@trendsmcp.ai
We will respond within 48 hours and aim to release a fix within 7 days of confirmation.
The following are in scope for security reports:
- Authentication and API key handling
- Data exposure or leakage via MCP tools
- Injection vulnerabilities in tool inputs
- Unauthorized access to trend data endpoints
- Denial of service attacks
- Rate limiting bypass
- Third-party data source vulnerabilities
We follow coordinated disclosure. Once a fix is released, we will publicly acknowledge the reporter (unless anonymity is requested).