Skip to content

Security: convictional/agent-plugins

SECURITY.md

Security Policy

Reporting a Vulnerability

If you believe you've found a security vulnerability in the Convictional plugin, please report it privately to compliance@convictional.com. Do not open a public issue or pull request for security reports.

Please include:

  • A description of the issue and its potential impact.
  • Steps to reproduce, or a proof of concept.
  • The affected skill, manifest, or component, and any relevant versions.

We'll acknowledge your report within three business days and keep you updated as we investigate. Please give us a reasonable opportunity to address the issue before any public disclosure.

Scope

This repository is a read-only mirror of the Convictional plugin source, published automatically from Convictional's main repository. It contains the marketplace catalog, the plugin manifest, the MCP server declaration, and the bundled skills — it does not host the Convictional service itself.

Reports about the hosted Convictional service or MCP server (https://convictional.com/mcp) are also welcome at the address above; they're routed to the same team.

There aren't any published security advisories