Security

Report a vulnerability

HowToPrompts is a small project with a public surface. If you have found a security issue, we want to hear about it — and we will work with you to get it fixed.

Reporting a vulnerability

Email security@howtoprompts.com. If you get no reply within a couple of days, use cihancs88@gmail.com as a fallback.

A good report includes:

  • Clear, reproducible steps — the exact request, URL, or interaction.
  • The impact you believe it has, and what an attacker could actually do with it.
  • A minimal proof of concept (screenshot, short script, or request/response pair).
  • Your name or handle if you would like credit.

We aim to acknowledge every report within 72 hours and will keep you updated as we investigate and ship a fix. Please do not open a public issue or post details before we have had a chance to respond.

Scope

In scope

  • howtoprompts.com and its subpages.
  • The HowToPrompts admin interface and API.

Out of scope

  • Volumetric or application-level denial-of-service, load testing, and traffic flooding.
  • Social engineering of HowToPrompts staff, users, or contractors, and physical attacks.
  • Vulnerabilities in third-party services we depend on (GitHub, the npm registry, Hostinger, and similar) — report those to the vendor.
  • Automated scanner output with no demonstrated, concrete impact.
  • Missing "best practice" HTTP headers or configuration hardening without a working exploit that depends on them.

Guidelines

  • Do not destroy, modify, or exfiltrate data that is not yours. Use test accounts and stop at proof of access.
  • Do not access, download, or store other users' personal data. If you encounter it, stop and tell us.
  • Do not run automated scanning that degrades or disrupts the service for others.
  • Keep findings confidential and give us a reasonable window to fix an issue before disclosing it publicly.

Safe harbor

If you make a good-faith effort to follow this policy, we consider your research authorized. We will not pursue or support legal action against you for accidental, good-faith violations, and we will help clarify scope if you are unsure. If legal action is brought by a third party against someone who complied with this policy, we will make it known that the activity was authorized.

Rewards

There is no paid bug bounty at this time. We do credit reporters publicly on this page or in release notes, with your permission, and we are grateful for every valid report.

Data & sources

All listing data on HowToPrompts — repos, MCP servers, skills, agents, tools, prompts, animations, and radar items — is pulled from public APIs and feeds, then re-expressed and organized. We do not host or resell third-party content, and attribution links point back to the original source. Questions about specific content, corrections, or takedown requests go to hello@howtoprompts.com.

Last updated 2026-09-04. Machine-readable contact: /.well-known/security.txt.