Skip to content

Security: NightSquawk/appfolio-mcp-server

SECURITY.md

Security Policy

Supported Versions

This project follows semantic versioning. Only the latest published release on npm (@nightsquawktech/appfolio-mcp-server) receives security fixes.

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Instead, report privately via one of:

Please include:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce (a minimal repro is very helpful)
  • The affected version(s)

We will acknowledge reports within a reasonable timeframe and keep you updated as we investigate and fix the issue. Once a fix is released, we will credit reporters (unless anonymity is requested) in the release notes.

Scope

This server is a thin MCP catalog/proxy layer over the AppFolio Reports and Database APIs. It does not store AppFolio data at rest. See the "Security & write safety" section of the README for guidance on credential scoping and the write-gate limitations of the current version.

There aren't any published security advisories