generated: '2026-08-04' method: searched probe: true policy: - https://github.com/lukkatech/lukka-plugin-claude/blob/main/lukka/SECURITY.md contact: - plugin-support@lukka.global reporting: channel: email private_disclosure_required: true subject_convention: - tag: '[PLUGIN-SECURITY]' scope: 'Plugin code: commands, skills, agents, hooks, processors; .mcp.json configuration and OAuth flow; audit-logging hook and logged data' - tag: '[MCP-SECURITY]' scope: 'Hosted MCP servers: aml, uda, pricing, refdata, analytics, news and predmar .mcp.lukka.tech' public_issues: explicitly disallowed for security vulnerabilities upstream_referral: https://www.anthropic.com/responsible-disclosure-policy for Claude Code / Anthropic platform issues bug_bounty: null gaps: - No /.well-known/security.txt on lukka.tech or any API host (404). - No responsible-disclosure or security page on lukka.tech (/security 404). - The published disclosure policy covers the Claude plugin and the MCP servers only - there is no published disclosure channel for the REST data APIs or the corporate surface. evidence: - source: https://github.com/lukkatech/lukka-plugin-claude/blob/main/lukka/SECURITY.md kind: SECURITY.md http_status: 200 fetched: '2026-08-04' - source: https://lukka.tech/.well-known/security.txt kind: security.txt http_status: 404 fetched: '2026-08-04' - source: https://lukka.tech/security kind: disclosure page http_status: 404 fetched: '2026-08-04'