Files
jhonny-editor/code/SECURITY.md
T
João Henrique b541f502ba feat: initial commit - Jhonny Editor
- Adicionado estrutura completa do projeto
- Configurado MCP server para Premiere Pro
- Adicionado documentação e skills
- Configurado Gitignore para o projeto
2026-09-08 09:59:31 -04:00

31 lines
1.3 KiB
Markdown
Executable File

# Security Policy
## Supported Versions
| Version | Supported |
| ------- | ------------------ |
| latest | :white_check_mark: |
## Reporting a Vulnerability
If you discover a security vulnerability in this project, **please do not open a public GitHub issue**.
Instead, report it by opening a [GitHub Security Advisory](https://github.com/kavyrattana/pp-mcp/security/advisories/new) (or contact the maintainer directly via GitHub).
Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce or a proof-of-concept
- Any suggested mitigations, if known
You can expect an acknowledgement within **48 hours** and a resolution timeline within **7 days** for critical issues.
## Security Considerations
This MCP server executes ExtendScript inside Adobe Premiere Pro via a CEP plugin. Please note:
- **Script validation** blocks dangerous patterns (`eval()`, `new Function()`, `System.callSystem()`) in user-provided scripts
- **`sendRawCommand()`** bypasses validation and should only be used by trusted clients
- The file-based IPC bridge writes temporary files to the system temp directory — ensure your temp directory has appropriate permissions
- This tool grants AI assistants significant control over Premiere Pro; only connect trusted MCP clients