Please do not open a public issue for a suspected security vulnerability.
Use GitHub private vulnerability reporting when available. Otherwise contact the maintainer privately through a channel published on the maintainer's GitHub profile.
Useful reports include reproducible details about credential handling, update integrity, local command execution, model synchronization, path/isolation boundaries, or accidental disclosure of runtime state. Do not include unrelated secrets or personal data.
Security fixes target the current main branch.