NamoID is an identity platform, so security reports must be handled privately.
Email security@namoid.in. Do not open a public GitHub issue.
Please include the affected CLI version, operating system, reproduction steps, impact, and an optional suggested fix. Remove all real credentials and personal data from reports and logs. We aim to acknowledge reports within 48 hours and provide a triage decision within five business days.
- Credential or environment-value disclosure
- Plugin release verification or installation bypasses
- Unsafe command execution or path handling
- Authentication, authorization, or MCP setup weaknesses caused by the CLI
- Dependency or supply-chain vulnerabilities that affect shipped behavior
If you act in good faith, avoid service disruption and unnecessary data access, and allow reasonable time for remediation before disclosure, NamoID will not pursue legal action for your security research.