Skip to content

Security: coco-research/coco

Security

SECURITY.md

Security policy

Reporting a vulnerability

If you find a security issue in Coco, please do not open a public issue.

Instead, report privately:

  1. Open a draft security advisory on GitHub, or
  2. Email the maintainer directly (contact via GitHub profile)

Include:

  • Description of the issue
  • Steps to reproduce
  • Affected files / skills / adapters
  • Impact assessment (what an attacker could do)
  • Suggested fix if you have one

Response

We aim to respond within 7 days and ship a fix or mitigation within 30 days for confirmed issues. You'll be credited in the release notes if you wish.

Scope

Coco is a library of markdown artifacts and shell installers. The most likely security concerns:

Concern Severity Notes
Malicious skill content (prompt injection) medium Skills are markdown; review before installing third-party additions
Adapter install.sh symlink behavior low Symlinks point only into the cloned repo; non-symlink files are left in place
Hardcoded credentials high Coco ships zero secrets; report any you find immediately
Supply-chain via plugin recommendations medium Skills must not `curl

Bootstrap installer behavior

bin/coco-bootstrap.sh (the bash <(curl -fsSL ...) one-liner) clones the pinned release tag (see PINNED_TAG in that script, kept in sync with package.json), not floating main. It then pauses for interactive confirmation before installing — it displays the cloned commit's hash, date, and message, and asks [y/N] before running install.sh. This is a deliberate behavior change from the prior zero-friction flow, added so users piping a remote script directly to their shell get a chance to verify what they're about to run.

Pass --yes or set COCO_BOOTSTRAP_YES=1 to preserve the old unattended behavior for CI or scripted installs. The npm CLI wrapper (bin/coco.js) uses the same tag pin.

Out of scope

  • Issues in third-party AI tools (Claude Code, Cursor, Codex, etc.) — report to those projects
  • Issues in external plugins listed in docs/recommended-plugins.md — report to plugin authors
  • Issues in MCP servers — report to https://github.com/modelcontextprotocol/servers

Disclosure

We follow coordinated disclosure: report → acknowledge → fix → public disclosure. Please give us a reasonable window to ship a fix before publishing details.

There aren't any published security advisories