Please do not open a public issue for a suspected vulnerability in the scanner, plugin packaging, or installation flow.
Use the repository's Security tab and select Report a vulnerability. Include the affected file or command, the impact, reproduction steps, and a suggested fix when possible. Reports about Apple's review process that do not expose a security issue belong in a rejection-case issue or a discussion.
This project does not collect credentials or contact Apple on a developer's behalf. Remove tokens, signing material, personal data, and unpublished app details from every report and reproduction.