If you discover a security vulnerability, please report it responsibly.
- Do not open a public GitHub issue.
- Email tamish@megallm.io with a description of the vulnerability and steps to reproduce.
- You will receive a response within 48 hours.
The following are in scope:
- Remote code execution
- Privilege escalation
- Sandbox escapes
- Data exfiltration via MCP tool calls
- Injection attacks (prompt injection, command injection)
The following are out of scope:
- Denial of service via resource exhaustion
- Social engineering
- Physical attacks
We follow coordinated disclosure. After a fix is released, we will publish a security advisory on GitHub.