spell-sync is a local CLI. It does not send data over the network, run a server, or execute
remote code. It reads and writes spell-check dictionary files on your machine when you run
Collect / Update (CLI pull / push) and related commands.
Report security issues privately via GitHub Security Advisories.
Do not post exploit details in public issues before a fix is available.
See also Contributing.
On macOS, writing some system dictionary paths may require Full Disk Access for your terminal. That is an OS permission model, not network exposure.