Skip to content

Security: JavierCollipal/android-security-toolkit

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.x.x
< 1.0

Reporting a Vulnerability

We take the security of this project seriously. If you discover a security vulnerability within the Android Security Toolkit, please follow responsible disclosure practices.

How to Report

  1. DO NOT create a public GitHub issue for security vulnerabilities
  2. DO NOT disclose the vulnerability publicly before it has been addressed
  3. Email your findings to the maintainers with:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fixes (if any)

What to Expect

  • Acknowledgment: Within 48 hours
  • Initial Assessment: Within 1 week
  • Resolution Timeline: Varies based on severity
  • Credit: Security researchers will be credited (unless anonymity is requested)

Security Best Practices for Users

When using these security tools:

  1. Authorization: Only test systems you own or have explicit permission to test
  2. Environment: Use isolated test environments when possible
  3. Data Protection: Never expose sensitive data in logs or reports
  4. Updates: Keep tools updated to the latest version
  5. Configuration: Never commit .env files or credentials

Scope

In Scope

  • Security vulnerabilities in the tools themselves
  • Issues that could lead to unauthorized access
  • Data exposure risks
  • Injection vulnerabilities

Out of Scope

  • Issues in third-party dependencies (report to the respective projects)
  • Social engineering
  • Physical attacks
  • Already known issues listed in documentation

Recognition

We appreciate the security research community's efforts in keeping this project secure. Responsible disclosure helps everyone!

Contact

For security concerns, contact the maintainers through GitHub or the email specified in the repository.

Thank you for helping keep the Android Security Toolkit secure!

There aren’t any published security advisories