This plugin contains a publishing skill and remote MCP connection settings. It bundles no credentials, server implementation, background process or local PlayDrop CLI. OAuth credentials stay in the connected client. Tools run with the signed-in PlayDrop user's permissions. A public upload or update publishes the game; a private upload stays visible only to you until you make it public. Signed upload URLs are temporary credentials; never log, share, or commit them. Follow your agent's approval prompts before publishing.
Report suspected vulnerabilities privately to support@playdrop.ai, including version, reproduction steps and impact. Use the public issue tracker for ordinary bugs and feature requests.