Skip to content

Security: droidrun/mobilerun-mcp

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you believe you've found a security vulnerability in mobilerun-mcp, please report it privately rather than opening a public issue or pull request.

Contact: security@droidrun.ai

Please include as much detail as you can:

  • A description of the vulnerability and its potential impact.
  • Steps to reproduce, or a proof-of-concept if available.
  • Any relevant logs, requests, or configuration.

We'll acknowledge your report and work with you on a fix and a coordinated disclosure timeline. Please give us a reasonable amount of time to investigate and address the issue before disclosing it publicly.

Scope

This applies to the code in this repository (packages/tools, packages/server). For issues with the Mobilerun platform or API itself that aren't specific to this MCP server's code, see the security/support channels documented for the relevant droidrun/Mobilerun repository.

Supported Versions

This project is pre-1.0 and does not yet maintain multiple supported release branches. Fixes land on main.

There aren't any published security advisories