MUGSHOT Security Policy
Scope
MUGSHOT is currently a macOS preview candidate. Windows, iOS, Android, and store builds are not publicly supported. We accept reports of suspected authentication bypasses, unintended external transmission, artifact/signing tampering, permission misuse, and other vulnerabilities affecting a public candidate.
Report privately
Do not post an unpatched issue in a public issue, social post, or ntfy topic. Email yamamoto@mizukichilab.com with the subject MUGSHOT security report.
Include only what is necessary:
- affected version, source, OS, and device
- expected impact and required conditions
- safe minimal reproduction steps or proof of concept
- an email address for follow-up
Do not send a real passcode, ntfy topic, evidence photo, signing key, personal data, or another person’s device data. If a sensitive attachment appears necessary, first send a summary and agree with us on an encrypted transfer method.
Response and coordinated disclosure
We aim to acknowledge a report within three business days, provide initial triage within seven business days, and update the reporter at least every fourteen days. These are targets, not guarantees. After validating impact, revoking credentials where needed, fixing and testing, and publishing a new version, we will coordinate disclosure with a reasonable update period for users. We will offer credit on request for lawful, good-faith research.
General support
Setup, compatibility, false alarms, and feature requests are not vulnerability reports. Use the Support page.