Reporting a vulnerability in Wasit

Report privately first. Do not open a public issue for a security problem.

Email repmoonasci@gmail.com with:

  • What the problem is and what an attacker could do with it
  • Steps to reproduce, ideally against the bundled fixture servers
  • The versions involved (@wasit/core, Node, and the relevant SDK versions)

You should get an acknowledgement within 72 hours. If a fix is warranted, it will be released before public discussion of the details, and you will be credited unless you prefer otherwise.

Things that are in scope: key material leaking into output, logs, or MCP tool arguments; a destructive check running without both required opt-ins; a check that reports PASS without actually verifying what its pass criteria in CHECKS.md claim.

Things that are not: the fact that some checks spend money, or that the tool will run against a target you were not authorised to test. Both are documented above and are properties of the tool working as designed.