Acceptable Use Policy
Last updated: March 2026
Purpose
This Acceptable Use Policy ("AUP") is a standalone document that supplements our Terms of Service. It is maintained separately so it can be updated independently as the platform evolves and new abuse patterns emerge. Violations of this AUP constitute a violation of the Terms of Service.
Prohibited Content
You may not publish or distribute bundles or other content that:
- Contains malware, viruses, trojans, worms, or other malicious code
- Contains child sexual abuse material (CSAM) or content that exploits or endangers minors
- Infringes on the intellectual property rights of others, including copyrights, trademarks, and trade secrets
- Contains content that is unlawful under applicable law
Prohibited Conduct
You may not:
- Attempt unauthorized access to the Platform, other users' accounts, or systems connected to the Platform
- Harvest, collect, or store credentials or authentication tokens of other users
- Use Platform compute resources for cryptocurrency mining or unrelated workloads
- Squat on namespaces — registering organization or bundle names with no intent to publish legitimate content, including for the purpose of resale
- Circumvent rate limits, quotas, or other technical restrictions
- Scrape or collect data from the Platform through automated means beyond what the public API permits
- Resell or sublicense Platform services without prior written authorization
- Interfere with or disrupt the Platform or its infrastructure
Bundle-Specific Rules
In addition to the general rules above, bundles specifically must not:
- Embed live credentials, API keys, private keys, or other secrets — use environment variables or secret management references instead
- Be designed to exploit known vulnerabilities in systems, networks, or other software without clear documentation that the bundle is intended for authorized security testing
- Contain obfuscated code intended to hide malicious behavior from review or scanning
Enforcement
Musher may take any of the following actions in response to AUP violations, at our sole discretion:
- Issue a warning to the account holder
- Remove or restrict access to specific bundles or content
- Temporarily suspend account access
- Permanently terminate the account
The severity of the response will be proportional to the violation. Where practical, we will notify you before taking action and provide an opportunity to remedy the violation. However, we reserve the right to act immediately when necessary to protect the Platform or its users.
If you believe enforcement action was taken against your account in error, you may submit an appeal to [email protected] within 30 days. We will review appeals and respond within 10 business days.
Reporting Violations
If you become aware of content or conduct that violates this AUP, please report it to [email protected]. Include as much detail as possible, including the bundle name or URL, a description of the violation, and any supporting evidence. We investigate all reports and will respond to acknowledge receipt within 2 business days.