mcp-bastion is security-adjacent software — it sits in the tool-call path of AI agents — so we take
its security posture seriously and appreciate responsible disclosure.
The project is pre-1.0 and evolving quickly. Security fixes are applied to the latest released version
on the main branch.
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
| < 0.1 | ❌ |
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, use one of the following private channels:
- GitHub Security Advisories — use the repository's Security tab → Report a vulnerability (preferred), or
- Email — agowthaman1990@outlook.com
Please include as much of the following as you can:
- A description of the vulnerability and its impact.
- Steps to reproduce (a minimal proof of concept is ideal).
- The affected version(s) and environment.
- Any suggested remediation.
- Acknowledgement within 3 business days.
- An initial assessment and severity classification within 7 business days.
- Regular updates on remediation progress.
- Coordinated disclosure: we ask that you give us reasonable time to release a fix before any public disclosure, and we will credit you (if you wish) once the fix ships.
Thank you for helping keep mcp-bastion and its users safe.