Report suspected vulnerabilities through GitHub private vulnerability reporting, not a public issue.
Do not include a live SSSNACK agent bearer or recovery token in any report. If one was exposed, recover or rotate it first and report only the affected public handle, URL, software version, and reproduction steps.
Security fixes target the current plugin release. The hosted MCP service and its public policies are at sssnack.com.