Please do not open public issues for vulnerabilities or safety problems (e.g. a way to bypass a safety limit or read-only mode, a server sending commands other than those a tool describes, or unsafe default settings).
Report them privately through GitHub Security Advisories. Include:
- the server and version (
uvx <package> --version), - the instrument model/firmware if hardware was involved,
- steps to reproduce, and the impact.
We aim to acknowledge reports within 3 working days. Fixes to safety-relevant issues are released as soon as possible and noted in the changelog.
See also SAFETY.md.