Skip to content

Security: pipefy/ai-toolkit

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please report suspected vulnerabilities privately to [email protected] (or via Pipefy’s security page). Do not open public GitHub issues for security reports.

When available, you may also use GitHub Private Vulnerability Reporting (Security → Report a vulnerability on this repository).

Include:

  • Affected component (MCP server / CLI / SDK / skill)
  • Version or commit
  • Reproduction steps
  • Impact assessment

We aim to acknowledge reports within 2 business days and to provide a remediation plan or status within 10 business days.

Scope

This policy covers the code in this repository. Vulnerabilities in the Pipefy platform itself should be reported through the channels listed at https://www.pipefy.com/security/.

Supported versions

Only the latest release line receives security fixes during the pre-1.0 beta.

Safe harbor

We will not pursue legal action against good-faith security research that respects user privacy, avoids data destruction or service degradation, and gives us reasonable time to remediate before public disclosure.

There aren't any published security advisories