Stellary · Vulnerability Disclosure

Stellary Vulnerability Disclosure

Vulnerability disclosure

Stellary runs a coordinated vulnerability disclosure program on Hackerone.

project-managementproductivityAI-agentsagent-orchestrationMCPremote-mcpdeveloper-toolsSaaScollaboration
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

stellary-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-01'
method: searched
source: https://github.com/Anymfah/stellary-mcp/blob/main/SECURITY.md
program:
  present: true
  type: private disclosure policy (no bug bounty)
  policy_url: https://github.com/Anymfah/stellary-mcp/blob/main/SECURITY.md
  raw_url: https://raw.githubusercontent.com/Anymfah/stellary-mcp/main/SECURITY.md
  contact: security@stellary.co
  contact_method: email
  bounty: false
  platform: none
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  scope_guidance: >-
    "Include the affected MCP method or tool, the impact, and reproducible steps when possible."
  reporter_instructions:
  - Report privately by email to security@stellary.co
  - Do not open a public GitHub issue for a suspected vulnerability
  - Do not include access tokens, personal data or customer workspace data in a report
  response_commitment: >-
    "We will acknowledge a valid report and coordinate remediation and disclosure directly with the
    reporter." No time-bound SLA is stated.
  safe_harbor: not stated
security_txt:
  present: false
  probed:
  - {url: 'https://stellary.co/.well-known/security.txt', status: 404}
  - {url: 'https://api.stellary.co/.well-known/security.txt', status: 404}
  gap: >-
    The disclosure policy exists but is only discoverable from the GitHub MCP discovery repo. An
    RFC 9116 security.txt on stellary.co pointing at the same policy and security@stellary.co would
    make it findable from the domain a reporter actually lands on. This is the single cheapest
    security-surface fix available to Stellary.
credential_guidance:
  source: https://github.com/Anymfah/stellary-mcp/blob/main/SECURITY.md
  points:
  - The MCP endpoint requires a bearer token; never commit a real token.
  - Revoke an exposed token immediately in Stellary account settings and reissue with minimum scopes.
  - Revoke an OAuth connection from Workspace settings -> MCP connections.
  - Stellary never sends the client the private tokens attached to a workspace agent.
note: >-
  Recorded as searched, not probed: the policy is a real, first-party published document in the
  provider's own public repository (github.com/Anymfah -- the same org named as maintainer in
  apis.yml and as repository in the official MCP registry record), fetched 2026-09-01 at HTTP 200.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/stellary-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.