Skip to content

Security

Security & disclosure

Last updated 2026-10-06 · machine-readable: /.well-known/security.txt

Reporting an issue in this site

Email hello@protocolprobe.com with what you found and how to reproduce it. Please don’t access other people’s data, degrade the service, or run automated scanners at volume.

What we find in MCP servers

  • We don’t publish unconfirmed security findings about a named server.
  • Runtime tests run only in an isolated sandbox, and only against servers we are allowed to test. We don’t actively probe third-party servers without authorisation.
  • When we contact a project, we do it through its own published channel.