Skip to content
This repository was archived by the owner on Oct 3, 2026. It is now read-only.

Security: suprsend/claude-code-plugin

Security

SECURITY.md

Security

Reporting Vulnerabilities

If you discover a security vulnerability in this plugin, please do not open a public issue. Instead, email [email protected] with details.

We'll acknowledge your report within 48 hours and work with you to resolve it.

Security Considerations

Service Tokens

Authentication uses service tokens created in Account Settings → Service Tokens. Tokens stored in profiles are kept locally by the CLI in your home directory. They are never committed to this repo — the .gitignore excludes all .env files.

  • Never hardcode tokens in .mcp.json or any checked-in file
  • Prefer environment variables or profiles over --service-token flags, since flags can appear in shell history or process listings
  • Use suprsend profile add --name default --service-token <TOKEN> to store tokens securely via the CLI
  • Rotate service tokens regularly via the SuprSend Dashboard and follow the principle of least privilege

MCP Server Transport

  • stdio (default): Communication happens over local process stdin/stdout. No network exposure.
  • SSE: Opens a local HTTP endpoint. Only use this in trusted network environments.

Skills

Skills are read-only reference material. They do not make API calls, store credentials, or execute code against your workspace.

Skills are bundled from the suprsend/skills repo and committed to this repository. A CI workflow checks weekly for upstream changes and auto-opens a PR if skills drift. For development, you can rebuild skills locally with make build. To pin to a specific version, set SKILLS_BRANCH to a tag or commit reference:

SKILLS_BRANCH=v1.0.0 make build

There aren't any published security advisories