If you believe you have found a security issue in any artifact in this repository — particularly the MFA shim prototype or test harness — please do not open a public issue.
Instead, report privately by emailing the maintainers. Include:
The maintainers will acknowledge your report within seven days, work with you to understand and validate the issue, and coordinate a public disclosure timeline once a fix or mitigation is available.
This security policy applies to:
mfa-shim/prototype/)test-harness/)This security policy does not apply to:
This is research output, not a regulated product. Vulnerability reports are addressed on a best-effort basis. There is no service-level agreement.