Security
If you discover a security vulnerability in Manufact Cloud or mcp-use, email [email protected]. Please don't post vulnerability details in a public issue. Include the affected product, steps to reproduce, and potential impact. Test only accounts and resources you own, and don't access other users' data.
We aim to acknowledge reports within 48 hours and provide an initial assessment within one week. Remediation timelines depend on severity. We'll coordinate with you on remediation and disclosure. Reporting a vulnerability does not guarantee a bounty; any rewards would follow separately published program rules.