Responsible disclosure
Report vulnerabilities privately to security@potion.sh with a minimal, safe reproduction.
Security
Potion treats uploaded archives, redirects, remote endpoints, premium objects, credentials, and logs as separate trust boundaries.
Report vulnerabilities privately to security@potion.sh with a minimal, safe reproduction.
Release and premium archives remain private and immutable; signed access is short-lived and authorized.
Tokens, passwords, payment data, keys, and raw MCP secrets are excluded from responses, logs, and audits.