Lukka · Vulnerability Disclosure

Lukka Vulnerability Disclosure

Vulnerability disclosure

Lukka publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CryptoDigital AssetsMarket DataReference DataPricingBlockchainAMLComplianceFinancial-ServicesAnalyticsPrediction MarketsMCP
Program: security.txt present

Disclosure Policy

Policy

Security Contact

Contact
plugin-support@lukka.global

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-04'
method: searched
probe: true
policy:
- https://github.com/lukkatech/lukka-plugin-claude/blob/main/lukka/SECURITY.md
contact:
- plugin-support@lukka.global
reporting:
  channel: email
  private_disclosure_required: true
  subject_convention:
  - tag: '[PLUGIN-SECURITY]'
    scope: 'Plugin code: commands, skills, agents, hooks, processors; .mcp.json configuration and OAuth flow; audit-logging
      hook and logged data'
  - tag: '[MCP-SECURITY]'
    scope: 'Hosted MCP servers: aml, uda, pricing, refdata, analytics, news and predmar .mcp.lukka.tech'
  public_issues: explicitly disallowed for security vulnerabilities
  upstream_referral: https://www.anthropic.com/responsible-disclosure-policy for Claude Code / Anthropic platform issues
bug_bounty: null
gaps:
- No /.well-known/security.txt on lukka.tech or any API host (404).
- No responsible-disclosure or security page on lukka.tech (/security 404).
- The published disclosure policy covers the Claude plugin and the MCP servers only - there is no published disclosure
  channel for the REST data APIs or the corporate surface.
evidence:
- source: https://github.com/lukkatech/lukka-plugin-claude/blob/main/lukka/SECURITY.md
  kind: SECURITY.md
  http_status: 200
  fetched: '2026-08-04'
- source: https://lukka.tech/.well-known/security.txt
  kind: security.txt
  http_status: 404
  fetched: '2026-08-04'
- source: https://lukka.tech/security
  kind: disclosure page
  http_status: 404
  fetched: '2026-08-04'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/lukka-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.