If you discover a security vulnerability in this plugin, please do not open a public issue. Instead, email [email protected] with details.
We'll acknowledge your report within 48 hours and work with you to resolve it.
Authentication uses service tokens created in Account Settings → Service Tokens. Tokens stored in profiles are kept locally by the CLI in your home directory. They are never committed to this repo — the .gitignore excludes all .env files.
- Never hardcode tokens in
.mcp.jsonor any checked-in file - Prefer environment variables or profiles over
--service-tokenflags, since flags can appear in shell history or process listings - Use
suprsend profile add --name default --service-token <TOKEN>to store tokens securely via the CLI - Rotate service tokens regularly via the SuprSend Dashboard and follow the principle of least privilege
- stdio (default): Communication happens over local process stdin/stdout. No network exposure.
- SSE: Opens a local HTTP endpoint. Only use this in trusted network environments.
Skills are read-only reference material. They do not make API calls, store credentials, or execute code against your workspace.
Skills are bundled from the suprsend/skills repo and committed to this repository. A CI workflow checks weekly for upstream changes and auto-opens a PR if skills drift. For development, you can rebuild skills locally with make build. To pin to a specific version, set SKILLS_BRANCH to a tag or commit reference:
SKILLS_BRANCH=v1.0.0 make build