Security fixes go to the latest published release of each repository.
Use GitHub's private vulnerability reporting from the repository's Security tab, or email hello@scalably.io. Do not open a public issue for a suspected vulnerability.
Include the affected version or commit, the operating system and client (Claude Code, Codex, Claude Desktop) version, the smallest safe reproduction, expected and observed behavior, and whether credentials or user data may have been exposed.
Do not include real credentials, client data, or private transcripts. Use a synthetic fixture.
Our MCP servers and hooks run locally with the permissions of the user who installed them, under the user's own API keys. They do not send data anywhere except the vendor API they wrap, and they store nothing persistently unless the README says otherwise.