Please do not disclose a vulnerability in a public issue. Use GitHub's private security-advisory reporting flow for this repository. If that flow is not available, email contact@cloudmol.org.
Include the affected version, reproduction steps, impact, and any suggested mitigation. Do not include real API keys or private research data.
ChatMol Lab can run shell commands, Python programs, MCP servers, plugins, and model-selected tools on the user's computer. Review approval prompts and only install plugins or MCP servers from sources you trust. Use a dedicated workspace and least-privilege provider credentials for sensitive work.
The maintainers do not request API keys in issues or support conversations.