If you discover a security vulnerability in Project Compass, please report it privately. Do not open a public GitHub issue for security problems.
- Use GitHub Private Vulnerability Reporting ("Report a vulnerability" under the repository's Security tab), or
- Contact the maintainers through the channel listed in the repository's contact information.
Please include:
- A description of the vulnerability and its potential impact.
- Steps to reproduce, or a proof of concept.
- Affected version(s) or commit SHA.
We aim to acknowledge new reports within 5 business days and to provide an initial assessment within 10 business days. We will keep you informed of remediation progress and coordinate disclosure timing with you.
This project is an MCP server that orchestrates LLM calls. When reporting,
note that it relies on third-party LLM provider APIs and on API keys supplied
via environment variables (ANTHROPIC_API_KEY, OPENAI_API_KEY). Never
include real API keys, credentials, or proprietary data in a report.
Security fixes are applied to the latest released version on the default branch. Older versions are not maintained unless otherwise stated.