Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -270,6 +270,7 @@ Prefer `argv` over a shell `command` string when you can — fewer quoting surpr
- **Token = master key** — Scope the service account tightly; rotate immediately if leaked; never commit tokens or MCP configs with secrets.
- **Prefer references** — `op://…` + `op_run` beat pasting passwords into prompts or files.
- **Least privilege** — Dedicated automation vaults beat sharing your whole account.
- **Reporting vulnerabilities** — Open a public issue; see [SECURITY.md](SECURITY.md).

---

Expand Down
22 changes: 22 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
# Security Policy

## Reporting a vulnerability

Security issues in this project are handled **in public**. Please open a [GitHub issue](https://github.com/CakeRepository/1Password-MCP/issues/new) with the full details so anyone can review the report and help fix it.

A useful report includes:

- **Affected version** — the `@takescake/1password-mcp` version you tested.
- **Impact** — what an attacker, a malicious prompt, or a crafted tool call can achieve.
- **Reproduction** — minimal steps, tool inputs, or a failing test.
- **Suggested fix** — optional. Pull requests are welcome.

**Never include real secrets.** Redact service account tokens, real `op://` references, and any revealed values before posting. If a token was exposed while testing, rotate it in 1Password.

## Supported versions

Fixes ship in the latest release only. Upgrade to the newest `4.x` to stay patched.

## After a fix

Confirmed vulnerabilities are fixed in a patch release, listed under **Security** in [CHANGELOG.md](CHANGELOG.md), and published as a GitHub Security Advisory crediting the reporter.
Loading