Security fixes focus on the latest public TinyAgent release and current development source. Older preview and beta versions may not receive backported fixes.
Report vulnerabilities through GitHub private vulnerability reporting. Include the affected version, device and Android version, access mode, reproduction steps, expected impact, and minimal redacted evidence.
Do not include API keys, OAuth tokens, ADB private keys, signing keys, or private conversations. Test only devices and accounts you own or are authorized to test.
Stock mode operates with the app's Android permissions. Developer and Root operations require separately authorized access to the same phone. The WebView must not expose privileged operations to arbitrary websites. Credentials must not appear in logs or shared artifacts.
Official APKs are distributed through GitHub releases. Compare a downloaded APK with that release's SHA256SUMS.txt. The official certificate fingerprint is below. An update must match the installed app's signing identity; do not uninstall to bypass a mismatch.
보안 수정은 최신 공개 릴리스와 현재 개발 소스를 우선 지원합니다. 이전 프리뷰·베타 버전에 수정이 소급 적용되지 않을 수 있습니다.
취약점은 GitHub 비공개 취약점 제보로 알려주세요. 영향받는 버전, 기기와 Android 버전, 실행 모드, 재현 순서, 예상 영향과 비밀을 제거한 최소 증거를 포함하세요.
API 키·OAuth 토큰·ADB 개인키·서명키·개인 대화는 포함하지 마세요. 본인 소유이거나 테스트 허가를 받은 기기와 계정만 사용하세요.
Stock은 앱의 Android 권한으로 실행됩니다. Developer·Root 작업은 같은 폰에 별도로 허용된 권한이 필요합니다. WebView가 임의의 웹사이트에 권한이 필요한 작업을 노출해서는 안 되며, 인증 정보가 로그나 공유 파일에 나타나서는 안 됩니다.
공식 APK는 GitHub 릴리스에서 배포합니다. 다운로드한 파일을 해당 릴리스의 SHA256SUMS.txt와 비교하세요. 공식 인증서 지문은 아래와 같습니다. 업데이트는 설치된 앱과 서명이 같아야 하며, 서명 불일치를 피하려고 앱을 삭제하지 마세요.
安全修复优先针对 TinyAgent 最新公开版本及当前开发代码。旧的预览版和 Beta 版本可能不会获得修复回移。
请通过 GitHub 私密漏洞报告提交漏洞。请包含受影响版本、设备和 Android 版本、访问模式、复现步骤、预期影响及已脱敏的最小证据。
不要附带 API 密钥、OAuth 令牌、ADB 私钥、签名密钥或私人对话。仅测试你拥有或获准测试的设备和账户。
Stock 模式使用应用自身的 Android 权限。Developer 和 Root 操作需要对同一部手机单独授权。WebView 不得向任意网站开放特权操作,凭据不得出现在日志或共享文件中。
官方 APK 通过 GitHub Releases发布。请将下载文件与该版本的 SHA256SUMS.txt 比对。官方证书指纹如下。更新必须与已安装应用的签名身份一致;不要为了绕过签名不匹配而卸载应用。
Official package: io.github.gplaider.tinyagent
Certificate SHA-256:
c34483dc3b7228cede2e128ccd66cab193e78804686a58ea25ba318568afc9d2
The certificate fingerprint identifies the signer. Each APK has its own separate file checksum in the release. 인증서 지문은 서명자를 식별합니다. APK 파일 체크섬은 릴리스마다 별도입니다. 证书指纹用于识别签名者;各版本 APK 的文件校验和另行发布。