Skip to content

Security: animepics/miku-code

Security

SECURITY.md

Security Policy

Supported versions

MikuCode is currently a development-stage project. Security fixes are made against the default branch; no release versions have a formal support window.

Reporting a vulnerability

Do not report security vulnerabilities in a public issue, discussion, or pull request. Use the repository’s private vulnerability reporting form to create a confidential report. If GitHub reports that private vulnerability reporting is unavailable, contact the repository maintainers through their GitHub profile with “MikuCode security report” in the subject; do not disclose exploit details publicly while waiting for a response.

Include a concise impact description, affected commit/version/platform, reproducible steps or a minimal proof of concept, and any suggested mitigation. Remove credentials, personal data, and unrelated shell history. We will acknowledge valid reports, investigate them, and coordinate disclosure timing when practical; no response or disclosure timeline is guaranteed yet.

Scope notes

MikuCode launches the user-selected local shell and displays its output. Reports involving commands intentionally entered into that shell should distinguish expected terminal behavior from an unintended privilege boundary or data disclosure. The persisted session snapshot may contain command output and is stored in the user’s Application Support directory; local access to that file is outside the application’s intended protection boundary.

There aren't any published security advisories