Stellary · Vulnerability Disclosure
Stellary Vulnerability Disclosure
Vulnerability disclosure
Stellary runs a coordinated vulnerability disclosure program on Hackerone.
project-managementproductivityAI-agentsagent-orchestrationMCPremote-mcpdeveloper-toolsSaaScollaboration
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-09-01'
method: searched
source: https://github.com/Anymfah/stellary-mcp/blob/main/SECURITY.md
program:
present: true
type: private disclosure policy (no bug bounty)
policy_url: https://github.com/Anymfah/stellary-mcp/blob/main/SECURITY.md
raw_url: https://raw.githubusercontent.com/Anymfah/stellary-mcp/main/SECURITY.md
contact: security@stellary.co
contact_method: email
bounty: false
platform: none
platforms_checked: [HackerOne, Bugcrowd, Intigriti]
scope_guidance: >-
"Include the affected MCP method or tool, the impact, and reproducible steps when possible."
reporter_instructions:
- Report privately by email to security@stellary.co
- Do not open a public GitHub issue for a suspected vulnerability
- Do not include access tokens, personal data or customer workspace data in a report
response_commitment: >-
"We will acknowledge a valid report and coordinate remediation and disclosure directly with the
reporter." No time-bound SLA is stated.
safe_harbor: not stated
security_txt:
present: false
probed:
- {url: 'https://stellary.co/.well-known/security.txt', status: 404}
- {url: 'https://api.stellary.co/.well-known/security.txt', status: 404}
gap: >-
The disclosure policy exists but is only discoverable from the GitHub MCP discovery repo. An
RFC 9116 security.txt on stellary.co pointing at the same policy and security@stellary.co would
make it findable from the domain a reporter actually lands on. This is the single cheapest
security-surface fix available to Stellary.
credential_guidance:
source: https://github.com/Anymfah/stellary-mcp/blob/main/SECURITY.md
points:
- The MCP endpoint requires a bearer token; never commit a real token.
- Revoke an exposed token immediately in Stellary account settings and reissue with minimum scopes.
- Revoke an OAuth connection from Workspace settings -> MCP connections.
- Stellary never sends the client the private tokens attached to a workspace agent.
note: >-
Recorded as searched, not probed: the policy is a real, first-party published document in the
provider's own public repository (github.com/Anymfah -- the same org named as maintainer in
apis.yml and as repository in the official MCP registry record), fetched 2026-09-01 at HTTP 200.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/stellary-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.