Skip to content

Security: johnlawson-dev/citation-gap-mcp

Security

SECURITY.md

Security policy

Reporting a vulnerability

Do not disclose vulnerabilities, credentials, tokens, account information or exploit details in a public GitHub issue.

Use GitHub's private security-advisory reporting feature for this repository if enabled. If it is unavailable, use the private contact method published on the Citation Gap website.

Include:

  • A clear description of the issue
  • Affected URL or component
  • Reproduction steps using non-sensitive test data
  • Potential impact
  • Suggested remediation, if known

Allow reasonable time for investigation before public disclosure.

Scope

This repository contains public documentation, not the production implementation. Reports about the hosted endpoint, authentication flow or hosted reports should still be submitted privately.

Secrets

Never commit API keys, OAuth credentials, cookies, tokens, customer data or Cloudflare secrets to this repository.

There aren't any published security advisories