Please report vulnerabilities privately to support@monologue.to. Do not open a public issue containing credentials, OAuth tokens, private note content, or reproduction data from a real account.
The plugin uses Monologue's hosted OAuth MCP endpoint and requests read-only note access. This repository contains no service credentials.