Please do not open a public GitHub issue for security vulnerabilities.
Instead, open a GitHub private security advisory or email the maintainer directly via GitHub profile.
We will respond within 7 days and coordinate a disclosure timeline with you.
- Credential leakage (
.envhandling, keychain storage) - Privilege escalation via Accessibility / Input Monitoring APIs
- Remote code execution via agent subprocess spawning
- XSS or injection in the Electron renderer
- Issues requiring physical access to the machine
- Denial-of-service against local processes