generated: '2026-09-01' method: searched source: https://github.com/Anymfah/stellary-mcp/blob/main/SECURITY.md program: present: true type: private disclosure policy (no bug bounty) policy_url: https://github.com/Anymfah/stellary-mcp/blob/main/SECURITY.md raw_url: https://raw.githubusercontent.com/Anymfah/stellary-mcp/main/SECURITY.md contact: security@stellary.co contact_method: email bounty: false platform: none platforms_checked: [HackerOne, Bugcrowd, Intigriti] scope_guidance: >- "Include the affected MCP method or tool, the impact, and reproducible steps when possible." reporter_instructions: - Report privately by email to security@stellary.co - Do not open a public GitHub issue for a suspected vulnerability - Do not include access tokens, personal data or customer workspace data in a report response_commitment: >- "We will acknowledge a valid report and coordinate remediation and disclosure directly with the reporter." No time-bound SLA is stated. safe_harbor: not stated security_txt: present: false probed: - {url: 'https://stellary.co/.well-known/security.txt', status: 404} - {url: 'https://api.stellary.co/.well-known/security.txt', status: 404} gap: >- The disclosure policy exists but is only discoverable from the GitHub MCP discovery repo. An RFC 9116 security.txt on stellary.co pointing at the same policy and security@stellary.co would make it findable from the domain a reporter actually lands on. This is the single cheapest security-surface fix available to Stellary. credential_guidance: source: https://github.com/Anymfah/stellary-mcp/blob/main/SECURITY.md points: - The MCP endpoint requires a bearer token; never commit a real token. - Revoke an exposed token immediately in Stellary account settings and reissue with minimum scopes. - Revoke an OAuth connection from Workspace settings -> MCP connections. - Stellary never sends the client the private tokens attached to a workspace agent. note: >- Recorded as searched, not probed: the policy is a real, first-party published document in the provider's own public repository (github.com/Anymfah -- the same org named as maintainer in apis.yml and as repository in the official MCP registry record), fetched 2026-09-01 at HTTP 200.