name: Motomarks Vulnerability Disclosure generated: '2026-09-09' method: searched source: https://github.com/motomarks/motomarks-mcp/blob/main/SECURITY.md note: >- Published disclosure policy lives in the official motomarks/motomarks-mcp GitHub repository SECURITY.md (fetched raw, HTTP 200, 2026-09-09). No /.well-known/security.txt is served on any host (404 on motomarks.io) and no bug-bounty program (HackerOne/Bugcrowd/Intigriti) was found. policy: channel: support@motomarks.io with "SECURITY" in the subject line public_issues: prohibited for vulnerabilities acknowledgement_sla: within 3 business days scope: - The hosted MCP endpoint at https://motomarks.io/api/mcp and its OAuth flow - Manifests and setup instructions distributed in the motomarks-mcp repository user_guidance: - Prefer OAuth over long-lived API keys - Never commit secret keys (sk_...) to source control - Review and revoke connected OAuth clients and API keys in the dashboard - Only connect trusted MCP clients (prompt-injection caution) bug_bounty: none found security_txt: served: false probe: https://motomarks.io/.well-known/security.txt returned 404 (2026-09-09)