This repository is the public Skill for the hosted CentricMem librarian. It does not contain API keys, pairing tokens, or owner passwords.
Please do not open a public issue for a security report.
Email zeyu@poppyg.com, or use GitHub private vulnerability reporting if it is enabled.
We aim to acknowledge reports within 48 hours and ship a patch within 7 days for critical issues that affect the Skill, host MCP, or the connect flow.
Include:
- What you found and how to reproduce it
- Affected install path (
npx skills add, host MCP athttps://mem.centricmem.com/mcp, website) - Whether any user data was accessed
- Agent keys, owner session cookies, Stripe secrets, R2 credentials
- Instructions to paste a key into chat
path=keep of arbitrary librarian-disk files- Steps that make an agent print a key value (dumping a credential file to show a key) instead of a fingerprint
Authenticate by asking the agent to send a /connect?device= link. Enter the key on that page.