← Files RiversideARCHIVED FILE
SECURITY.md
1.71 KB · Oct 8, 2026 · 12:02 UTC
# Security Policy ## Reporting a vulnerability Email **security@riverside.fm**. For a critical or actively-exploited issue, put `[CRITICAL]` in the subject line. Please include enough detail to reproduce: the affected tool or endpoint, the request you sent, what you observed, and what you expected. If a proof of concept touches data, use an account you own. We work to a coordinated-disclosure model. Please give us a reasonable opportunity to ship a fix before disclosing publicly, and do not access, modify, or retain data belonging to anyone other than yourself while investigating. ## Scope This repository contains the plugin package only — skills, manifests, and packaging validators. It holds no credentials and runs no service. Reports about the MCP server itself are in scope for the address above even though its source is not in this repository. That covers: - `https://mcp.riverside.com/mcp` — the MCP endpoint the plugin connects to. - `https://riverside.com/auth` — the OAuth 2.0 authorization server that issues the plugin's tokens. - Any of the tools the plugin exposes returning data the authenticated caller should not be able to reach. Out of scope: findings that require a compromised end-user device or client, rate-limiting and volumetric issues without a demonstrated security impact, and reports generated by an automated scanner with no accompanying analysis. ## Revoking access You can disconnect the plugin at any time from your MCP client. Tokens are not silently refreshed, so disconnecting stops the client from obtaining a new one. To revoke an already-issued token immediately rather than waiting for it to expire, contact support and ask for the Riverside MCP grant on your account to be revoked.
SHA-256: 57be735bae95ee34e6e1c84a042c569ce3bd9a34e91f0f066f79bcb5e228d3f2