Reporting a vulnerability in Wasit
Report privately first. Do not open a public issue for a security problem.
Email repmoonasci@gmail.com with:
- What the problem is and what an attacker could do with it
- Steps to reproduce, ideally against the bundled fixture servers
- The versions involved (
@wasit/core, Node, and the relevant SDK versions)
You should get an acknowledgement within 72 hours. If a fix is warranted, it will be released before public discussion of the details, and you will be credited unless you prefer otherwise.
Things that are in scope: key material leaking into output, logs, or MCP tool arguments; a destructive check running without both required opt-ins; a check that reports PASS without actually verifying what its pass criteria in CHECKS.md claim.
Things that are not: the fact that some checks spend money, or that the tool will run against a target you were not authorised to test. Both are documented above and are properties of the tool working as designed.
