Report vulnerabilities in these plugins, the Offline Protocol CLI they launch, or the hosted MCP server to security@offlineprotocol.com. Do not open a public issue, pull request or discussion.
Include the affected file or version, a description and impact, and steps to reproduce. We acknowledge reports within 48 hours and send an initial assessment and remediation timeline within 7 days. The default coordinated disclosure window is 90 days from acknowledgment.