[media-types] [IANA #1450625] application/vnd.vimina .vma registration request

"Amanda Baber via RT" <[email protected]> Thu, 07 May 2026 19:41:23 +0000
Newsgroups gmane.ietf.types
Message-ID <[email protected]>
Hi Murray,

Resending this revision from April 30th.

thanks,
Amanda

On Thu Apr 30 18:42:58 2026, amanda.baber wrote:
> Hi Murray,
> 
> Could you check this revised registration request? They provided this
> list of changes:
> 
> 1. Security considerations: Added an explicit statement that the
> payload is executable, per RFC 6838.
> 2. Section 2.1: Expanded with a concrete checklist of what reviewers
> should look for in untrusted scripts.
> 3. Interoperability considerations: Provided a brief rationale
> explaining why this is the correct answer for a vendor-specific type
> handled by the Vimina runtime.
> 4. Published specification: Verified and updated the URL to ensure it
> is publicly accessible.
> 
> thanks,
> Amanda
> 
> =====
> 
> Name: Sunny Lynn
> 
> Email: [email protected]
> 
> Media type name: application
> 
> Media subtype name: vnd.vimina.vma
> 
> Required parameters: N/A
> 
> Optional parameters: charset,version
> 
> Encoding considerations: binary
> 
> Security considerations:
> 
> This media type defines an executable payload. VMA files contain
> automation scripts that are interpreted and executed by the Vimina
> runtime environment.
> 
> 1.Script Execution
> VMA scripts can control mouse and keyboard input, which may pose
> security risks if scripts from untrusted sources are executed.
> 
> 2.Recommended Practices
> 2.1. Review scripts before execution
> Before executing scripts from external sources, reviewers should
> examine the script for:
> Unauthorized input injection, keystroke capture, or credential
> harvesting
> Unexpected or unauthorized execution of external programs
> Unauthorized file system access, modification, or exfiltration
> Unintended network communication or data transmission
> Attempts to modify system settings or escalate privileges
> 2.2. Use sandboxing for untrusted scripts
> 2.3. Limit script permissions when possible
> 2.4. Log all script actions for audit purposes
> 
> 3.Dangerous Operations
> The following operations should require user confirmation:
> Sending input to password fields
> Executing external programs
> Modifying system settings
> 
> Interoperability considerations:
> This media type uses a text-based script format fully interpreted by
> the Vimina runtime. As a vendor-specific type intended primarily for
> the Vimina desktop automation tool, interoperability is governed by
> the Vimina implementation and its specification. The format does not
> depend on external encoding schemes or platform-specific binary
> structures.
> 
> Published specification:
> https://github.com/Sunse666/Vimina/blob/main/docs/VMA-Specification.md
> https://sunse666.github.io/Vimina-docs/
> 
> Applications which use this media: Vimina desktop automation tool
> 
> Fragment identifier considerations: N/A
> 
> Restrictions on usage: N/A
> 
> Provisional registration? (standards tree only): No
> 
> Additional information:
> 
> 1.Deprecated alias names for this type: N/A
> 2.Magic number(s): N/A
> 3.File extension(s): .vma
> 4.Macintosh file type code: N/A
> 5.Object Identifiers: N/A
> 
> General Comments: N/A
> 
> Person to contact for further information:
> 
> 1.Name: Sunny Lynn
> 2.Email: [email protected]
> 
> Intended usage: COMMON
> 
> Author/Change controller: Sunny Lynn

_______________________________________________
media-types mailing list -- [email protected]
To unsubscribe send an email to [email protected]