Skip to content

Security: pepabo/lolipop-mcp

Security

SECURITY.md

Security Policy

GMO Pepabo, Inc. takes the security of our software products and services seriously, including this repository (pepabo/lolipop-mcp) and the hosted MCP server at https://lolipop.jp/api/v1/mcp.

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Instead, please report them via email to security@pepabo.com.

To help us triage your report quickly, please include as much of the following information as you can:

  • The type of issue (e.g., token leak, command injection, credential exposure, supply chain)
  • Affected component (hosted endpoint or this repository's metadata)
  • Location of the affected code or endpoint (branch/commit hash or direct URL)
  • Any special configuration required to reproduce the issue
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if possible)
  • Impact of the issue, including how an attacker might exploit it

Response

We will acknowledge your report within a reasonable timeframe and keep you informed of the progress toward a fix. We appreciate coordinated disclosure and will credit reporters who wish to be acknowledged.

Scope

This policy covers:

  • Metadata in this repository
  • The hosted Lolipop MCP endpoint at https://lolipop.jp/api/v1/mcp

All security vulnerabilities — whether in this repository, the hosted MCP endpoint, or the Lolipop Rental Server website / control panel itself — should be reported to security@pepabo.com (see GMO Pepabo's vulnerability reporting policy). Only non-security, general product inquiries should go to https://lolipop.jp/support/.

There aren't any published security advisories