Skip to content

Security: valkor-ai/loom

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Use GitHub's private vulnerability reporting flow for this repository when it is available. Include a clear description, affected versions, reproduction steps or proof of concept, impact, and any suggested mitigation.

If private reporting is unavailable, contact the maintainers through the project Discord and ask for a private reporting channel. Do not include exploit details in the public message.

Scope

Reports involving the Loom MCP server, installers, release artifacts, bundled runtime dependencies, and supported agent integrations are in scope.

Disclosure

Please give maintainers reasonable time to investigate and release a fix before publicly disclosing a vulnerability. We will acknowledge a valid report, assess its impact, and coordinate remediation and disclosure with the reporter.

There aren't any published security advisories