Skip to content

Security: kosli-dev/mcp-server

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest released version is supported. Fixes ship forward in a new release rather than being backported to earlier versions, so please upgrade before reporting an issue.

If you installed the .mcpb bundle by hand, note that it does not auto-update — download the latest from Releases and reinstall.

Reporting a Vulnerability

Please send all reports to security@kosli.com and include:

  • Clear description of the vulnerability
  • Steps to reproduce
  • Potential impact assessment
  • Any supporting evidence (screenshots, logs, PoC)

This repository contains the Kosli MCP server, which is a thin client over the Kosli API. If you find a vulnerability in the Kosli API or web app — including one you discovered while using this server — please report it to the same address rather than opening a public issue here.

Our Commitment

Integrity is a core value at Kosli. We have a strong track record of working fairly and openly with security researchers, and we're committed to transparent communication throughout the disclosure process. We will acknowledge receipt, assess the finding, and respond with our determination. If we classify the vulnerability differently than reported, we'll explain our reasoning.

There aren't any published security advisories