Do not open a public issue for security problems. Report privately, either via
GitHub's private vulnerability reporting
on this repository (Security → Report a vulnerability), or by emailing
simon.pl.mak@gmail.com with SECURITY in the subject.
Include: affected component (mcp-server/, scripts, opencode.json), reproduction
steps, and impact. We aim to acknowledge within 3 business days.
The latest commit on main is the only supported version.
This repository must never contain secret values. Provider and MCP credentials are
referenced only through {env:VAR} placeholders and are supplied at runtime from the
operator's environment (~/.env.workbench or the platform's secret store).
The mcp-server/ clone tool writes only an empty template (~/.env.workbench,
mode 600) to target machines; it never reads, transmits, or commits secret values.
gitleaksruns on every push and pull request (.github/workflows/secret-scan.yml).- GitHub secret scanning and push protection are enabled on the repository.