Only the latest released version is supported. Fixes ship forward in a new release rather than being backported to earlier versions, so please upgrade before reporting an issue.
If you installed the .mcpb bundle by hand, note that it does not auto-update — download the latest from Releases and reinstall.
Please send all reports to security@kosli.com and include:
- Clear description of the vulnerability
- Steps to reproduce
- Potential impact assessment
- Any supporting evidence (screenshots, logs, PoC)
This repository contains the Kosli MCP server, which is a thin client over the Kosli API. If you find a vulnerability in the Kosli API or web app — including one you discovered while using this server — please report it to the same address rather than opening a public issue here.
Integrity is a core value at Kosli. We have a strong track record of working fairly and openly with security researchers, and we're committed to transparent communication throughout the disclosure process. We will acknowledge receipt, assess the finding, and respond with our determination. If we classify the vulnerability differently than reported, we'll explain our reasoning.