security
Security
keygrant handles other people’s credentials, so we take reports seriously and would much rather hear about a problem than have it stay hidden.
Reporting a vulnerability
Please report privately through GitHub’s private vulnerability reporting rather than a public issue. Include what you found, how to reproduce it, and what you think the impact is. We’ll acknowledge it, keep you updated, and credit you in the fix unless you’d rather not be named.
If that form isn’t available to you, open a regular issue that only says you have a security report and asks for a private channel. Please leave the details out of it.
In scope
- A secret value reaching the model’s context through keygrant: the MCP tools, their output, or redaction gaps.
- Bypassing the approval dialog, or reusing a grant for a command the user never saw.
- The cloud service learning a secret value, forging a device, a pairing or an approval, or one account reaching another’s data.
- The approver console at app.keygrant.app signing something the user didn’t approve.
Known limits, not vulnerabilities
These are documented in the threat model:
- A command you approve can send the secret anywhere it likes.
- Redaction can miss encodings it doesn’t know, and doesn’t cover files.
- Malware running as your OS user can read your keystore.
New ways around these are still welcome as reports: for example, an encoding we should add.