Maa skills and MCP servers may control Android devices, desktop windows, browsers, and local files. Treat configuration changes and runtime actions as privileged operations.
- Do not include credentials in skills, fixtures, logs, or MCP configuration examples.
- Keep browser sessions isolated by default and do not enable unrestricted file access automatically.
- Require explicit user intent before purchases, account changes, destructive clicks, or other high-risk actions.
- Report suspected vulnerabilities privately through the repository host's security advisory feature once the project is published.
Do not open a public issue containing secrets, private screenshots, device identifiers, or exploit details.