Security
Security guidance
Apply Potion's reporting, credential, archive, publishing, and premium-content security boundaries.
Report suspected vulnerabilities privately to security@potion.sh. Do not include access tokens, customer data, or exploit payloads beyond what is required to reproduce the issue.
User responsibilities
- Review artifact permissions and publisher trust before installation.
- Keep API keys, webhook secrets, and MCP secret values out of repositories and logs.
- Rotate a credential immediately after suspected exposure.
- Verify archive checksums and avoid untrusted mutable download mirrors.
Potion rate limits sensitive operations, sanitizes public content, keeps premium storage private, and maintains secret-free audit records.