Skip to content

Security: mmdju/orca-mcp

Security

SECURITY.md

Security Policy

Orca MCP is a read-only public service. There is nothing to log in to and no user data is stored.

  • All 21 tools are read-only. No tool can change, delete or publish anything.
  • No API keys are needed to use the hosted endpoint.
  • Upstream provider keys live server-side and are never exposed in responses.

Reporting a Vulnerability

Please do NOT open a public issue. Report privately via the Security tab (Advisories → Report a vulnerability).

There aren't any published security advisories