Do not open a public issue for a vulnerability or a prompt-capture privacy bug. Use GitHub's private vulnerability reporting for this repository.
Include the affected version, agent adapter, reproduction steps, impact, and any suggested mitigation. Avoid including real credentials or private writing samples.
Security-sensitive areas include secret redaction, local file permissions, hook input selection, unintended agent output capture, installer config merging, automatic-update integrity, telemetry payload boundaries, and export/delete behavior.
Only the latest release receives security fixes during the initial alpha period.