Only the latest published npm release (and matching git default branch) is supported for security fixes.
Please do not open a public GitHub issue for security vulnerabilities.
Report privately (for example via GitHub Security Advisories on this repository, or another private channel to the maintainer) and include:
- affected package version or commit
- environment (OS, Node.js, MCP client)
- reproduction steps
- observed impact
You should receive an acknowledgment when possible. Coordinated disclosure is preferred.
This project can control attached Android/iOS devices and store local artifacts. Unauthorized device actions and path/artifact handling issues are high priority.
- Prefer least privilege and explicit allowlists where the project provides them
- Do not commit secrets, tokens, or machine-specific credentials
- Treat local MCP servers as running with the privileges of the OS user that starts them