Zillapi · Vulnerability Disclosure

Zillapi Vulnerability Disclosure

Vulnerability disclosure

Zillapi runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

Real-EstatePropTechProperty DataZillowZestimateValuationAVMListingsMCPAI AgentREST API
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
nikhil@landkit.pro

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-09'
method: searched
probe: true
scope: open-source-repository-only
summary: >-
  Zillapi publishes a security policy, but only for its open-source agent-skills repository — not for
  the API service. There is no /.well-known/security.txt on either host, no bug bounty, and no
  disclosure page on zillapi.com. Recorded with that scope stated plainly rather than as a
  service-level VDP.
policy:
  - https://github.com/ZeroPointRepo/zillow-skills/blob/main/SECURITY.md
contact:
  - nikhil@landkit.pro
terms:
  subject_line: 'SECURITY: zillow-skills'
  public_issues: not permitted for security reports
  acknowledgement_sla: 72 hours
  fix_target: 14 days for confirmed issues
bug_bounty:
  program: null
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  found: false
probes:
  - {url: 'https://zillapi.com/.well-known/security.txt', status: 404}
  - {url: 'https://api.zillapi.com/.well-known/security.txt', status: 404}
  - {url: 'https://github.com/ZeroPointRepo/zillow-skills/blob/main/SECURITY.md', status: 200}
evidence:
  - source: https://github.com/ZeroPointRepo/zillow-skills/blob/main/SECURITY.md
    kind: security-policy
    fetched: '2026-08-09'
    excerpt: >-
      "Email nikhil@landkit.pro with the subject line `SECURITY: zillow-skills`. Please do not open
      public issues for security reports. We will acknowledge receipt within 72 hours and aim to
      publish a fix or mitigation within 14 days for confirmed issues."
gap: >-
  The API service itself has no published disclosure route. A researcher who finds a flaw in
  api.zillapi.com has no documented channel — the only published contact is a repo-scoped address for
  the skills bundle. An RFC 9116 /.well-known/security.txt on zillapi.com would close this.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/zillapi-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.