GMO Pepabo, Inc. takes the security of our software products and services seriously, including this repository (pepabo/lolipop-mcp) and the hosted MCP server at https://lolipop.jp/api/v1/mcp.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, please report them via email to security@pepabo.com.
To help us triage your report quickly, please include as much of the following information as you can:
- The type of issue (e.g., token leak, command injection, credential exposure, supply chain)
- Affected component (hosted endpoint or this repository's metadata)
- Location of the affected code or endpoint (branch/commit hash or direct URL)
- Any special configuration required to reproduce the issue
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if possible)
- Impact of the issue, including how an attacker might exploit it
We will acknowledge your report within a reasonable timeframe and keep you informed of the progress toward a fix. We appreciate coordinated disclosure and will credit reporters who wish to be acknowledged.
This policy covers:
- Metadata in this repository
- The hosted Lolipop MCP endpoint at
https://lolipop.jp/api/v1/mcp
All security vulnerabilities — whether in this repository, the hosted MCP endpoint, or the Lolipop Rental Server website / control panel itself — should be reported to security@pepabo.com (see GMO Pepabo's vulnerability reporting policy). Only non-security, general product inquiries should go to https://lolipop.jp/support/.