This repository holds a specification, a ratings dataset, and the tooling that validates and publishes them. Report here:
- A defect in the tooling or site that could harm someone running it
- A supply-chain concern with this repository or its release artifacts
- A rating or model flaw whose public discussion would meaningfully help an attacker before defenders can react
Please report responsibly rather than opening a public issue for those.
Vulnerabilities in Microsoft products or services — including Microsoft Entra ID, Microsoft Graph, and the permissions this standard describes — go to the Microsoft Security Response Center, not to us. We are documenting how risky permissions are, not maintaining the platform that grants them.
Ordinary disagreements about a rating are not security issues. A permission you believe is under-rated is a rating change request and benefits from being discussed in the open.
Use GitHub's private vulnerability reporting:
If that is unavailable to you, contact a maintainer directly and ask for a private channel. Do not include details in the first public message.
Please include what you found, how to reproduce it, what an attacker could achieve, and how you would like to be credited.
| Acknowledgement | Within 3 working days |
| Initial assessment | Within 10 working days |
| Fix or mitigation | Depends on severity; we will keep you updated |
| Credit | Offered by default, declined on request |
We are volunteers. We will be honest with you about timelines rather than promise a response time we cannot meet.
We follow coordinated disclosure. We will agree a disclosure date with you, publish an advisory when a fix ships, and credit you unless you prefer otherwise. Please give us a reasonable window before publishing — 90 days is our default, and we will usually be much faster.