Vincra reads and writes global coding-agent configuration, so security reports are taken seriously.
Security fixes are provided for the latest published version. Upgrade to the latest version before reporting an issue that may already be fixed.
Do not open a public issue for a suspected vulnerability or include credentials, private configuration, or exploit details in public discussions.
Use GitHub private vulnerability reporting to send:
- The affected Vincra version and operating system.
- The affected command or adapter.
- Reproduction steps using redacted or synthetic configuration.
- The impact and any suggested mitigation.
You will receive acknowledgement through the advisory. We will investigate, coordinate a fix and release when needed, and credit reporters who request attribution.
Vincra is designed to:
- Keep canonical configuration in
~/.vincraor the explicitVINCRA_HOMElocation. - Reject likely plaintext secrets in MCP environment values, headers, command arguments, and URLs.
- Preserve OAuth credentials in the coding agent that owns them.
- Use atomic writes, verified read-back, and rollback for managed changes.
- Hash and verify backup contents before restore.
- Avoid undocumented application databases and project-level configuration.
Users remain responsible for operating-system permissions on their home directory, environment variables, installed MCP servers, agent authentication, and reviewing configuration before an explicit import or sync.
Please allow time to investigate and release a fix before public disclosure. Once users have a safe upgrade path, the advisory can be published with mutually agreed attribution.