Skip to content

Security: descriptinc/descript-mcp

Security

SECURITY.md

Security

Reporting a vulnerability

If you find a security issue in this repository or in the Descript MCP server it connects to, please report it privately rather than opening a public issue.

  • Email: security@descript.com
  • Or use GitHub's private vulnerability reporting on this repository ("Security" tab → "Report a vulnerability").

Please include steps to reproduce and the potential impact. We will acknowledge your report and keep you informed as we investigate.

Scope

This repository contains plugin manifests, workflow guidance, and skills. It ships no runtime code other than a local validation script. Authentication to the Descript MCP server is handled by OAuth; no credentials are stored in this repo.

There aren't any published security advisories