If you discover a security vulnerability in Screencast MCP, please report it responsibly.
Do not open a public issue for security vulnerabilities.
Instead, report it privately through GitHub: Report a vulnerability (Security tab → "Report a vulnerability"). Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
We will acknowledge receipt within 48 hours and provide a timeline for resolution.
Only the latest release (currently the 0.x line published as
@tmhs/screencast-mcp on npm) receives security fixes. Upgrade to the newest
version before reporting.
The redact_region tool covers rectangles that the caller declares. It does not
detect secrets on its own, so it cannot redact a secret nobody pointed it at.
- The default
boxstyle writes a solid, filled rectangle. A solid fill is irreversible. Theblurandpixelatestyles are softer but can be partially recovered, soboxis the correct choice for an actual secret. - A region that falls outside the source frame is rejected, so an off-frame typo fails loudly instead of leaving the secret visible.
- Redaction re-encodes to a new file. Always review the output (for example with
sample_frames) before sharing, and delete the unredacted original if it is no longer needed.