Skip to content

Security: vectojs/numera-mcp

Security

SECURITY.md

Security Policy

Supported versions

Only the latest published version receives security fixes.

Reporting a vulnerability

Use GitHub private vulnerability reporting for vectojs/numera-mcp. Do not include secrets, private workbooks, or exploit payloads in a public issue.

Security model

The server confines all tool paths to its configured root, rejects symlink escapes, limits workbook and range work through the underlying codecs and tool caps, preserves source files, requires optimistic SHA-256 matching, and writes new outputs atomically. It performs no outbound network access.

There aren't any published security advisories