Security guidance — Plug docs

Security

Security guidance

Apply Plug's reporting, credential, archive, publishing, and premium-content security boundaries.

Report suspected vulnerabilities privately to security@plug.sh. Do not include access tokens, customer data, or exploit payloads beyond what is required to reproduce the issue.

User responsibilities

  • Review artifact permissions and publisher trust before installation.
  • Keep API keys, webhook secrets, and MCP secret values out of repositories and logs.
  • Rotate a credential immediately after suspected exposure.
  • Verify archive checksums and avoid untrusted mutable download mirrors.

Plug rate limits sensitive operations, sanitizes public content, keeps premium storage private, and maintains secret-free audit records.