Skip to content

Security: mcp-tool-shop-org/world-forge

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
4.x Yes
< 4.0 No

Reporting a Vulnerability

Email: 64996768+mcp-tool-shop@users.noreply.github.com

Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Version affected
  • Potential impact

Response timeline

Action Target
Acknowledge report 48 hours
Assess severity 7 days
Release fix 30 days

Scope

This tool operates locally only.

  • Data touched: user-created world project files (JSON) on local disk
  • No network egress — editor runs as a local dev server, no external API calls
  • No secrets handling — does not read, store, or transmit credentials
  • No telemetry is collected or sent

There aren’t any published security advisories