Email security reports to security@filepad.ai.
Do not open a public issue for vulnerabilities involving Agent Access secrets, request signing, workspace data exposure, or MCP tool permission bypasses.
Include:
- affected package and version
- affected API/tool/resource
- reproduction steps
- expected impact
Agent Access secrets are shown once in Filepad. Rotate a key if a secret is exposed.