Skip to content

Security: katekruger/descript-studio

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Report security issues through GitHub private vulnerability reporting — Security → Report a vulnerability on this repository. Please do not open a public issue for a security problem.

Expect an acknowledgement within 7 days and an assessment within 30 days. This is a personal project maintained on a best-effort basis; there is no paid support tier and no bounty.

What is in scope

This plugin is markdown instructions only — skills, commands, an agent definition, shared reference docs, and two JSON manifests. It ships no compiled code, no dependencies, and no build step. The realistic security surface is therefore:

  • Prompt-injection paths. A skill or reference doc that could be steered by untrusted content (a transcript, a filename, a lead's text) into taking an action the user did not ask for.
  • Over-broad instructions. A skill that tells the agent to publish, delete, or overwrite without an explicit request.
  • Manifest issues. A component path or MCP declaration that loads something unintended.
  • The bundled dist/descript-studio.plugin not matching the source it claims to be built from.

What is out of scope

  • Descript's own service and API. Report those to Descript directly. This plugin is an independent, unofficial client.
  • Vulnerabilities in Claude Code itself — report those to Anthropic.
  • The optional Figma and brand-voice connectors, which are third-party.

What this plugin touches

Worth knowing when assessing risk:

  • Network: one MCP server, https://api.descript.com/v2/mcp, over HTTPS with OAuth. The plugin stores no token; authentication is handled by the host. No other endpoint is contacted.
  • Filesystem: reads and writes ~/.descript-studio/ (the cached brand profile and any copied logo). descript-brand-setup also reads design-token and logo files the user points it at. Nothing else outside the plugin directory is written.
  • Never committed: no credentials, project IDs, composition IDs, brand profiles, or media are stored in this repository. The brand profile lives in the user's home directory precisely so it is never distributed.

Safety behavior

The plugin is designed to refuse two things regardless of phrasing, and these are worth reporting as bugs if they ever fail:

  • It never publishes unless publishing was explicitly requested or part of an approved build plan.
  • It duplicates a composition before the first destructive pass, because Descript's AI edits are not cleanly undoable.

There aren't any published security advisories