| Version | Supported |
|---|---|
| Latest | Yes |
If you discover a security vulnerability in recraft-mcp, please report it responsibly:
- Do not open a public GitHub issue for security vulnerabilities.
- Email security@bartwaardenburg.nl with:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- You will receive a response within 48 hours.
- API tokens are passed via environment variables and never logged or persisted to disk.
- Image data is transmitted to Recraft's API over HTTPS and is not cached locally.
- No filesystem access — this server does not read from or write to the local filesystem.
- Network scope — outbound requests are limited to
external.api.recraft.aiandregistry.npmjs.org.