Please do not open public issues for suspected security vulnerabilities.
Instead:
- Open a private GitHub security advisory for this repository.
- See GitHub's private vulnerability reporting guide if you are unfamiliar with the flow.
Security concerns will be treated with urgency due to the sensitive nature of the library.
Include:
- A clear description of the issue and impact.
- Reproduction steps or proof of concept.
- Affected versions/commits.
- Suggested mitigation if available.
proton-pass-community-mcpis an MCP wrapper aroundpass-cli; vulnerabilities in upstream Proton services/clients should also be reported to Proton through their official channels.- Do not include real credentials, vault contents, OTP values, or private keys in reports.