| Version | Supported |
|---|---|
| 1.x | ✅ Yes |
Please do not open a public GitHub issue for security vulnerabilities.
Report vulnerabilities privately via GitHub Security Advisories.
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
| Stage | Timeframe |
|---|---|
| Initial acknowledgement | Within 48 hours |
| Triage and severity assessment | Within 7 days |
| Fix or mitigation | Within 30 days for critical, 90 days for others |
| Public disclosure | After fix is released |
This tool is designed to analyze mobile apps for security issues.
- False negatives / positives → open a regular GitHub issue
- Vulnerabilities in the MCP server itself → report privately as above
- Pattern bypass or evasion techniques → report privately