# Security policy

## Reporting a vulnerability

Please report security issues privately through GitHub's security advisory form for this repository. Do not open a public issue for credential disclosure, redirect handling, or request-routing vulnerabilities.

## Credential handling

- `PI_XSEARCH_API_KEY` and `XAI_API_KEY` are read only when the tool executes.
- Credential values are not returned in tool output or details.
- Redirects are rejected before a bearer token can be forwarded to another endpoint.
- Remote endpoints must use HTTPS.
- Plain HTTP is allowed only for `localhost`, `127.0.0.1`, and `[::1]`.
- URLs containing embedded username or password fields are rejected.

A configured gateway is trusted with the search query and bearer token. Review and operate that gateway accordingly.

## Untrusted search results

Content returned from X is third-party input. The extension labels it as untrusted through Pi's prompt guidelines, but callers should still verify consequential claims against their source URLs.
