Security guidance — Potion docs

Security

Security guidance

Apply Potion's reporting, credential, archive, publishing, and premium-content security boundaries.

Report suspected vulnerabilities privately to security@potion.sh. Do not include access tokens, customer data, or exploit payloads beyond what is required to reproduce the issue.

User responsibilities

  • Review artifact permissions and publisher trust before installation.
  • Keep API keys, webhook secrets, and MCP secret values out of repositories and logs.
  • Rotate a credential immediately after suspected exposure.
  • Verify archive checksums and avoid untrusted mutable download mirrors.

Potion rate limits sensitive operations, sanitizes public content, keeps premium storage private, and maintains secret-free audit records.