MiniMax-AI / MiniMax-AI/MiniMax-MCP

Security: requesting a private disclosure contact

Open
#105 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
1.6k
Forks
284
PR merge metrics
No merged PRs in 30d

Description

Hi MiniMax team,

I've identified a security issue in MiniMax-MCP that I'd like to report privately and responsibly.

The repository doesn't have GitHub's "Report a vulnerability" (private security advisory) enabled, and I couldn't find a SECURITY.md, a security.txt, or a security contact.

Could you please either:

  • enable Private vulnerability reporting on this repo (Settings → Code security → Report a vulnerability), or
  • share a security email (and PGP key, if you use one)

so I can send the full technical write-up through a private channel? I'll keep everything private until you've shipped a fix, and I'm not including any details here to avoid public exposure.

Thanks,
Moshe Levi, LevinityCyber (info@levinitycyber.com)

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Check the repository's security settings for Private vulnerability reporting, then check whether SECURITY.md or security.txt exists. Done means contributors have a private reporting channel or a published security contact, with any supported PGP key details included.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
security
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Active
Clarity
Clearly specified
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.