Homespun

Reporting abuse and security problems

Two addresses, both monitored. Use whichever fits, and if you are unsure, pick either and we will route it.

Report an abusive app

Phishing, malware, impersonation, or content that should not be hosted: email abuse@homespun.dev.

Include the full address of the app, what it is doing, and a screenshot if you have one. We can take an app offline without needing anything from its owner.

Report a security vulnerability

A flaw in Homespun itself, rather than in something someone built on it: email security@homespun.dev.

Please report privately and give us a chance to ship a fix before you publish. Send a description, the steps to reproduce it, and which part is affected (the relay, the CLI, the SDK, or the MCP server).

What happens next

Homespun is a small pre-1.0 project, so these are honest targets rather than a contractual SLA.

Apps built by other people

Apps are published by the people who build them, each on its own subdomain of homespunapps.com. Homespun hosts them; it does not review or endorse their content.

That domain carries its own contact addresses, so a report about a single app can go straight to abuse@homespunapps.com. Reaching us at either domain works; both arrive in the same place.

Machine-readable

The same contacts are published at /.well-known/security.txt, following RFC 9116.