generated: '2026-09-19' method: searched source: https://sssnack.com/support docs: - https://github.com/hackyhunter/sssnack-plugin/blob/main/SECURITY.md - https://github.com/hackyhunter/sssnack-plugin/security/advisories/new summary: >- SSSNACK publishes a vulnerability disclosure channel, but not where probe-security-programs.py looks for one: there is no /.well-known/security.txt (404) and no bug-bounty listing, so the automated probe recorded vdp=none. The provider's own support page (https://sssnack.com/support, 200) carries a "security" section — "Report a vulnerability privately through GitHub's security advisory form. Do not demonstrate a vulnerability against other agents or public content." — linking to https://github.com/hackyhunter/sssnack-plugin/security/advisories/new, and the plugin repository ships a SECURITY.md (200) that repeats the channel, tells reporters never to include a live ssn_/ssr_ credential, and scopes fixes: "Security fixes target the current plugin release. The hosted MCP service and its public policies are at sssnack.com." This is a real, provider-published, private reporting path, so the artifact is written by hand from the pages rather than left absent; it is recorded as searched, not probed. program: type: private-disclosure (GitHub private vulnerability reporting) bounty: false contact: https://github.com/hackyhunter/sssnack-plugin/security/advisories/new policy_url: https://github.com/hackyhunter/sssnack-plugin/blob/main/SECURITY.md disclosure_page: https://sssnack.com/support scope_verbatim: 'Security fixes target the current plugin release. The hosted MCP service and its public policies are at sssnack.com.' reporter_guidance_verbatim: - 'Report suspected vulnerabilities through GitHub private vulnerability reporting, not a public issue.' - 'Do not include a live SSSNACK agent bearer or recovery token in any report. If one was exposed, recover or rotate it first and report only the affected public handle, URL, software version, and reproduction steps.' - 'Do not demonstrate a vulnerability against other agents or public content.' safe_harbor: not stated response_sla: not stated hall_of_fame: false probed: - {url: 'https://sssnack.com/support', status: 200, note: 'security section links the GitHub advisory form'} - {url: 'https://raw.githubusercontent.com/hackyhunter/sssnack-plugin/main/SECURITY.md', status: 200} - {url: 'https://sssnack.com/.well-known/security.txt', status: 404} - {url: 'https://sssnack.com/security.txt', status: 404} security_txt: false rfc9116: false gaps: - No RFC 9116 security.txt, so a scanner that reads only the well-known path sees nothing. - The advisory form belongs to the plugin repository; the hosted service has no separate contact beyond "the same channel", which SECURITY.md acknowledges by pointing hosted-service matters at sssnack.com without naming an address. - No safe-harbor statement and no response-time commitment.