NagaController requires sensitive system permissions (Accessibility and Input Monitoring), so security is taken seriously.
If you discover a security vulnerability, please report it by:
- Opening a private security advisory on GitHub (preferred)
- Go to the Security tab
- Click "Report a vulnerability"
Please include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fixes (optional)
- I'll acknowledge your report within 48 hours
- I'll work on a fix and keep you updated on progress
- Credit will be given to reporters (unless you prefer to remain anonymous)
Only the latest release receives security updates. Please update to the newest version before reporting issues.
Security issues include:
- Unauthorized access or privilege escalation
- Data exposure or keystroke logging beyond intended functionality
- Bypass of macOS security features
- Code injection vulnerabilities
Thank you for helping keep NagaController secure!