MacCrabRave
Documentation

Terms of Service

Terms for the MacCrab Rave plugin store — plugins are third-party software you install at your own risk; capability disclosure, the signed-supply-chain trust model, revocation, and takedown.

Version 2026-07-03. These plain-language terms govern use of the MacCrab Rave plugin store. They may be revised as the service evolves; the version in effect is always dated here, and submitters record the version they accepted. This is a plain-language summary, not legal advice.

These terms cover MacCrab Rave — the plugin catalog served at rave.maccrab.com and consumed by the MacCrab app — and the plugins distributed through it. By browsing the catalog, installing a plugin, or submitting one, you agree to the terms below. If you don’t agree, don’t use the store.

This document sits alongside the Privacy page (what we collect and don’t) and the Verification page (how to verify a plugin yourself). Read those too — the trust model described here is the same one those pages document.

Acceptable use

Use the store for its intended purpose: discovering, verifying, and installing forensic plugins for your own MacCrab installation. Don’t:

  • attempt to bypass, forge, or strip the catalog’s signatures or a plugin’s signature;
  • submit a plugin you don’t have the right to distribute, or that misrepresents what it does or what it reads;
  • use the submission or comment surfaces to distribute malware, spam, or unlawful content;
  • probe, scrape, or load the catalog API in a way intended to degrade the service for others;
  • impersonate another author or claim a vendor namespace that isn’t yours (see Reserved namespaces).

Plugins are third-party software you install at your own risk

A MacCrab plugin is software written by its author, not by MacCrab — even when it’s listed in this catalog. Listing a plugin means it passed the catalog’s vetting gates (signature verification, declared-capability consistency, and — for community plugins — a reproducible build from public source); it is not a warranty that the plugin is fit for your purpose, bug-free, or appropriate for any particular case or jurisdiction.

You install and run plugins at your own risk. You are responsible for deciding whether a given plugin is appropriate for your data and your use, and — where you run it against data belonging to others — for having the authority to do so.

Every plugin declares, in its signed manifest.json, exactly which macOS data it reads and which capabilities it uses — the files and databases it touches, any TCC-protected sources, and any network or process capability. The catalog surfaces these declarations on the plugin’s detail page so you can read them before you install.

At install time, MacCrab shows you the plugin’s declared capabilities and asks you to consent. Nothing is granted silently:

  • the App Sandbox confines the plugin to what it declared, and refuses anything it didn’t;
  • the catalog’s vetting rejects a plugin whose binary tries to do more than its manifest discloses (see Submit a plugin for the capability policy);
  • you can decline at the consent step, and you can remove an installed plugin at any time.

Capability disclosure is a description of what a plugin asks for, not a guarantee about how its author handles what it reads once it runs. Review the disclosure and the plugin’s own documentation before consenting.

First-party vs community channels

The catalog distributes plugins on two channels, and the distinction matters for what these terms cover:

  • official (first-party). Plugins built and signed by the MacCrab team, published from the signed catalog mirror. These are our own software.
  • contrib (community). Plugins from independent third-party authors, listed after vetting. They run under the same App Sandbox and the same signing requirements, but they are other people’s software, distributed through a community channel.

For community-channel plugins, the author — not MacCrab — is the party responsible for the plugin’s behaviour, its updates, its security response, and its compliance with any license or law. MacCrab operates the catalog and the vetting process; it does not author, control, or stand behind third-party plugins.

The contrib channel is open for submissions (owner-reviewed vetting; nothing is published until it passes and the catalog is re-signed). MacCrab does not yet run community plugins — that execution lane arrives with a future MacCrab release.

The signed-supply-chain trust model and revocation

The store’s security rests on a signed supply chain, not on trusting this website:

  • the catalog itself is Ed25519-signed by the MacCrab Rave project key;
  • each plugin is Ed25519-signed by its publisher key, recorded in the catalog entry;
  • community plugins must be reproducible from public source, so anyone can rebuild and confirm the bytes;
  • the MacCrab app verifies a signature before loading anything — an unsigned or tampered plugin does not load.

You do not have to take our word for any of this. The Verification page walks through verifying a plugin end-to-end without trusting the catalog.

Revocation. We publish a signed revocations.json. If a plugin or a publisher key is found to be malicious, compromised, or in breach of these terms, we can revoke it; a revoked plugin or key is rejected by MacCrab going forward. Revocation is the primary mechanism for pulling a bad plugin out of the supply chain after the fact — keep your MacCrab able to fetch the current revocation list.

No warranty; limitation of liability

The store and the plugins distributed through it are provided “as is” and “as available,” without warranty of any kind, express or implied, including (without limitation) any implied warranties of merchantability, fitness for a particular purpose, or non-infringement.

For third-party (community-channel) plugins in particular, MacCrab makes no warranty as to their quality, security, accuracy, or fitness, and disclaims liability for any loss or damage arising from your installation or use of them. The vetting gates reduce risk; they do not eliminate it.

To the maximum extent permitted by applicable law, MacCrab and its operator are not liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of data, arising out of your use of the store or any plugin obtained through it.

DMCA / takedown and reserved namespaces

Takedown. If you believe a listed plugin infringes your copyright or other rights, or violates these terms, contact maccrab@peterhanily.com with enough detail to identify the plugin and the basis of the complaint. We respond to valid copyright (DMCA-style) notices and to substantiated abuse reports, and may remove or revoke a listing while we review.

Reserved namespaces. The com.maccrab.* plugin-id namespace is reserved for first-party plugins; a community submission claiming it is rejected. A submission whose vendor label is confusingly close to the MacCrab brand is routed to manual owner review rather than auto-merged. See Namespace review in the submission docs.

Operator rights — removal and revocation

MacCrab, as operator of the store, may at its discretion and without prior notice:

  • decline, delist, remove, or revoke any plugin — including a first-party one — that is malicious, compromised, broken, mislabeled, infringing, or otherwise in breach of these terms;
  • revoke a publisher key via the signed revocation list;
  • remove a submission or comment, or restrict an account, for abuse, spam, or breach of acceptable use;
  • change the vetting policy, the channel model, or these terms (with the version of the terms in force recorded in the public repo).

These rights are about keeping the supply chain safe; they don’t transfer responsibility for a third-party plugin from its author to MacCrab.

Changes to these terms

We may update these terms; the current version lives in the public repository and the effective version is the one published here. Material changes that affect contributors will be noted before the contrib channel opens.

Contact

Questions, takedown notices, or security concerns: maccrab@peterhanily.com. Don’t post security issues in a public comment thread — see the Verification and Privacy pages for the trust and disclosure model.