# Security Policy Security fixes are applied to the latest release and the `main` branch. Report vulnerabilities privately through GitHub's **Security → Report a vulnerability** flow for this repository. Include affected versions, reproduction steps, impact, and any suggested remediation. Do not include real message contents, contact records, phone numbers, or attachment files. The project aims to acknowledge a report within 72 hours and provide an initial severity assessment within seven days. ## Local trust boundary This server runs with the permissions of the application that launches it. Full Disk Access can expose private local data beyond Messages, so users should grant it only to a trusted MCP client and review that client's tool confirmations and data policies.