Skip to content

Security: tokportal/cursor-plugin

Security

SECURITY.md

Security Policy

Please report security issues privately to security@tokportal.com. Do not open public issues for vulnerabilities, API key exposure, authentication bypasses, webhook signature problems, or package supply-chain concerns.

Include:

  • the package name and version,
  • the affected API operation (if known),
  • reproduction steps,
  • any TokPortal request ID (X-TokPortal-Request-ID) surfaced by SDK error diagnostics.

We acknowledge reports within 3 business days. Please give us a reasonable window to ship a fix before public disclosure.

Supported versions

Only the latest published version of each package receives security fixes.

There aren't any published security advisories