Zillapi · Vulnerability Disclosure

Zillapi Vulnerability Disclosure

Vulnerability disclosure

Zillapi runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

real estateproptechproperty datazillowzestimatevaluationAVMlistingsMCPAI agentREST API
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
nikhil@landkit.pro

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-09'
method: searched
probe: true
scope: open-source-repository-only
summary: >-
  Zillapi publishes a security policy, but only for its open-source agent-skills repository — not for
  the API service. There is no /.well-known/security.txt on either host, no bug bounty, and no
  disclosure page on zillapi.com. Recorded with that scope stated plainly rather than as a
  service-level VDP.
policy:
  - https://github.com/ZeroPointRepo/zillow-skills/blob/main/SECURITY.md
contact:
  - nikhil@landkit.pro
terms:
  subject_line: 'SECURITY: zillow-skills'
  public_issues: not permitted for security reports
  acknowledgement_sla: 72 hours
  fix_target: 14 days for confirmed issues
bug_bounty:
  program: null
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  found: false
probes:
  - {url: 'https://zillapi.com/.well-known/security.txt', status: 404}
  - {url: 'https://api.zillapi.com/.well-known/security.txt', status: 404}
  - {url: 'https://github.com/ZeroPointRepo/zillow-skills/blob/main/SECURITY.md', status: 200}
evidence:
  - source: https://github.com/ZeroPointRepo/zillow-skills/blob/main/SECURITY.md
    kind: security-policy
    fetched: '2026-08-09'
    excerpt: >-
      "Email nikhil@landkit.pro with the subject line `SECURITY: zillow-skills`. Please do not open
      public issues for security reports. We will acknowledge receipt within 72 hours and aim to
      publish a fix or mitigation within 14 days for confirmed issues."
gap: >-
  The API service itself has no published disclosure route. A researcher who finds a flaw in
  api.zillapi.com has no documented channel — the only published contact is a repo-scoped address for
  the skills bundle. An RFC 9116 /.well-known/security.txt on zillapi.com would close this.