# Security policy This plugin talks to **your** Gitea instance with **your** personal access token. Treat the token like a password. ## Report a vulnerability Email **security-reports@cursor.com** if the issue is in how Cursor loads plugins. For this repository, open a private security advisory on [MAKS-IT-COM/maksit-gitea-cursor](https://github.com/MAKS-IT-COM/maksit-gitea-cursor), or email [commercial@maks-it.com](mailto:commercial@maks-it.com). Do not file a public issue that includes tokens, secrets, or a working exploit. ## What this plugin does - Sends `Authorization: token …` only to `{GITEA_URL}/api/v1/...`. - Rejects absolute URLs, `..` path segments, and redirects that leave that API prefix. - Requires HTTPS except for localhost (override with `GITEA_ALLOW_HTTP=true` on a trusted network only). - Defaults to a curated toolset. Admin APIs, raw `gitea_request`, Actions secrets, runner tokens, and PAT create/delete are off until you set the matching env flag. ## What you should do - Create a Gitea token with the minimum scopes you need. Do not grant site-admin unless you also set `GITEA_ENABLE_ADMIN=true` and understand the risk. - Prefer `GITEA_READ_ONLY=true` for review-only agents. - Never commit `.env` files or paste tokens into issues, skills, or chat logs. - Trust self-signed certificates in the OS trust store. This plugin does not disable TLS verification.