Security updates are provided for the current minor release line.
| Version | Supported |
|---|---|
| 0.2.x | ✅ |
| < 0.2.0 | ❌ |
Audit Status: This project has not undergone a third-party security audit. We are committed to addressing all responsibly disclosed vulnerabilities.
If you discover a security vulnerability in mcp-seatbelt, please report it privately rather than opening a public issue.
Contact: william@banksey.com
What to include:
- Detailed description of the vulnerability
- Steps to reproduce (proof-of-concept code, tool names, configuration)
- Affected versions
- Any suggested mitigations or patches
PGP Key: Not required, but if you prefer encrypted communication, request our PGP key in your initial email.
Response time: We aim to acknowledge your report within 48 hours and provide an initial assessment within 5 business days.
We follow a 90-day responsible disclosure timeline:
- The vulnerability is reported privately to william@banksey.com
- Within 48 hours, we acknowledge receipt and begin triage
- Within 5 business days, we provide an initial assessment and severity rating
- A fix is developed and privately shared with the reporter for validation
- A release is published with the fix
- A public advisory is issued 90 days after the initial report, or sooner if both parties agree
If the vulnerability is actively being exploited, we may shorten the disclosure window and coordinate an emergency release.
We gratefully recognize the following individuals for responsibly disclosing security issues:
| Name | Issue | Date |
|---|---|---|
| — | — | — |
To be added to this list, report a valid vulnerability following the process above and indicate that you would like to be acknowledged.
Security issues in scope include:
- Policy bypass (deny rules not enforced, allowlist escapes)
- Request smuggling or injection via the JSON-RPC proxy
- Credential leakage through error messages, logs, or reports
- Arbitrary code execution via malicious server configurations
- Denial of service against the proxy server
- Template injection in report generation
- Issues in third-party MCP servers (report to the server's maintainer)
- Social engineering or phishing attacks
- Missing HTTP security headers not directly exploitable
- Denial of service via resource exhaustion in local-only proxy (without remote vector)