Skip to content

Security: ToxMCP/comptox-mcp

Security

SECURITY.md

Security Policy

Supported Versions

Security fixes are provided for the latest state of the main branch.

Version Supported
main Yes
Older branches/tags No

Reporting a Vulnerability

Please report suspected vulnerabilities through GitHub's private advisory channel:

Do not open public issues for security-sensitive reports.

When filing a report, include:

  1. A clear description of the issue and impact.
  2. Reproduction steps or a minimal proof of concept.
  3. Affected versions/commit hashes.
  4. Any suggested remediation, if available.

Response Expectations

Maintainers will aim to:

  1. Acknowledge new reports within 3 business days.
  2. Provide a status update or triage decision within 10 business days.
  3. Coordinate remediation and disclosure timing with the reporter.

There aren’t any published security advisories