Skip to content

Security: gensecaihq/mcp-poisoning-poc

Security

SECURITY.md

Security Policy

GenSecAI Security Research

This repository is maintained by GenSecAI, a non-profit community dedicated to AI security research.

Supported Versions

Version Supported
1.0.x
< 1.0

Reporting a Vulnerability

This repository contains security research demonstrating vulnerabilities. However, if you discover additional security issues:

  1. DO NOT open a public issue
  2. Email [email protected] with:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

Response Timeline

  • Initial Response: Within 48 hours
  • Status Update: Within 7 days
  • Resolution Target: Within 30 days for critical issues

Responsible Disclosure

GenSecAI follows responsible disclosure principles:

  1. Researchers given credit (unless anonymity requested)
  2. Coordinated disclosure with vendors
  3. Public disclosure after patches available
  4. Educational focus on defense

GenSecAI Bug Reporting

While we don't offer monetary rewards, we deeply appreciate security research contributions:

  • Recognition in our Hall of Fame
  • Invitation to GenSecAI research community
  • Co-authorship opportunities on security papers
  • Speaking opportunities at GenSecAI events

Security Best Practices

When using this research:

  1. Never use these techniques maliciously
  2. Only test on systems you own or have permission to test
  3. Follow local laws and regulations
  4. Report vulnerabilities responsibly
  5. Help build better defenses

Contact

About GenSecAI

A non-profit community using generative AI to defend against AI-powered attacks, building open-source tools to secure our digital future from emerging AI threats

There aren’t any published security advisories