Skip to content

Security: itallstartedwithaidea/MiniAgent

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly:

  1. Do NOT open a public GitHub issue
  2. Email: john@itallstartedwithaidea.com
  3. Include: description, steps to reproduce, potential impact

We will respond within 48 hours and work with you to address the issue.

Scope

  • MCP server credential handling
  • OAuth token storage and transmission
  • API key exposure in logs or error messages
  • Training data containing PII

Out of Scope

  • Google/Meta/Microsoft API vulnerabilities (report to those platforms directly)
  • Social engineering attacks
  • Denial of service

There aren’t any published security advisories