Only the latest released version of palette-mcp (and its corresponding
plugin/skill manifests in this repo) is supported with security fixes.
Please upgrade to the latest release before reporting an issue.
Please do not open a public GitHub issue for security vulnerabilities.
Report vulnerabilities privately by emailing security@spectrocloud.com. This sends your report to Spectro Cloud's security team for private triage.
Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce (proof-of-concept code or commands, if applicable)
- The affected version(s)
- Any suggested remediation, if you have one
- We aim to acknowledge new reports within 5 business days.
- We'll keep you updated as we investigate and work on a fix.
- We ask that you give us a reasonable window to release a fix before any public disclosure — we're happy to coordinate a disclosure timeline with you.
This repository ships binary releases and Claude Code plugin manifests for
palette-mcp. The MCP server source is maintained separately — if your
report concerns the server implementation rather than this repo's
distribution artifacts, please still report it here and we'll route it
internally.