Please report security vulnerabilities privately to jdsteel61@yahoo.com.au rather than opening a public issue. Credential-handling or API-key-related bugs in particular should be reported privately first.
nano-tools reads provider API keys from environment variables (for example ANTHROPIC_API_KEY). Keys are never written to logs, artifacts, or stored state. If you discover a path where credentials could leak into output, please report it privately.
The current release (0.1.0) receives security fixes. Older versions do not.