Skip to content

Security policy

The policy is SECURITY.md in the repository.

Report a vulnerability privately through GitHub Security Advisories, not in a public issue. Include a description, steps to reproduce and the potential impact. The policy states a response within 72 hours.

sui-mcp is a read-only MCP server that queries public Sui endpoints. It does not handle private keys, sign transactions or manage funds. Security-relevant areas include input validation of tool parameters, error handling that leaks no internal state, and the dependency supply chain.

What the process reads, writes and runs is listed in Security model.