Please use GitHub private vulnerability reporting for suspected security or privacy issues. Do not include authenticated page captures, copied practice content, cookies, access tokens, names, account identifiers, or score values.
Security-sensitive guarantees include:
- No extension-initiated external network traffic
- No remote code
- Storage limited to sanitized MKit-authored study records
- No active-exam, answer-submission, reset, or account-state behavior
- Fail-closed masking when a completed-review layout is unsupported
- Exact, narrow page access and the
storagepermission only
Security fixes are provided for the most recent tagged release.