Please do not report security vulnerabilities through public GitHub issues.
Report suspected vulnerabilities privately through the Apollo Trust Center, which is Apollo.io's official channel for responsible disclosure.
When reporting, please include as much of the following as you can:
- A description of the issue and its potential impact.
- Steps to reproduce, or a proof of concept.
- The affected component (this repository, or the hosted MCP server at
https://mcp.apollo.io/mcp). - Any relevant logs, versions, or configuration.
Please give us a reasonable amount of time to investigate and address the issue before any public disclosure.
This repository contains the Apollo MCP client configuration, plugin manifests, workflow skills, and registry metadata. The MCP server itself is hosted and operated by Apollo.io.
- Issues in this repository (configuration, plugin manifests, skills, registry metadata): report via the Apollo Trust Center, or, for non-sensitive bugs, open a regular issue on apolloio/apollo-mcp-plugin.
- Issues in the hosted Apollo.io platform or MCP server: report via the Apollo Trust Center.