Please do not open a public GitHub issue for security problems. Report them privately to Razorpay's security team through Razorpay's responsible disclosure channel.
Configuration only: plugin manifests, public MCP server URLs, READMEs and logos. No source code, credentials, internal hostnames or customer data are ever committed here.
- Every change goes through a pull request reviewed by
@razorpay/payments-ai-devs(CODEOWNERS). masteris protected: no direct pushes, at least one approving review, CI must pass.- CI runs
scripts/validate.py(https-only, allowlisted MCP hosts, no inline auth headers) and a gitleaks scan of the full history on every PR and push. - GitHub secret scanning and push protection are enabled on the repository.
- Adding a new MCP host to the allowlist requires security review.