Skip to content
Cosmopediaby Unity Nodes

Security Disclosure

How to report vulnerabilities in Cosmopedia. Machine-readable copy at /.well-known/security.txt.

Reporting

Email [email protected]. For non-security questions, use the contact form.

Please include reproduction steps, affected URL or endpoint, browser/agent, and any logs you have. If the issue is sensitive, request a PGP key in your first message and we will respond out-of-band.

Response timeline

  • 72h: initial acknowledgement.
  • 7d: severity assessment and patch plan or risk acceptance.
  • 30d: public disclosure once a fix is deployed, unless the reporter prefers earlier.

Scope

In scope:

  • cosmopedia.xyz and its subdomains.
  • /api/v1/* REST endpoints, /mcp MCP server, /api/feed/* feeds.
  • The metrics endpoint (/api/metrics).

Out of scope:

  • Rate-limit volume tests, denial-of-service, automated scanners.
  • Issues only reproducible with a custom client that disables CSP or modifies bundled JS.
  • Reports based on missing security headers without a concrete exploit.
  • Third-party services we depend on (OpenAI, GitHub, cosmos.directory) - report those upstream.

Safe harbour

Good-faith research on this scope, conducted without privacy or availability damage, will not lead to legal action. Please avoid touching production data of other users (IPs).

Acknowledgements

No reports received yet. Future reporters who opt-in will be credited here with name + GitHub/Twitter handle.