Please do not open a public issue for a suspected vulnerability.
Report security problems privately through GitHub Security Advisories. Include the affected command or package, reproduction steps, expected impact, and any suggested mitigation.
You should receive an acknowledgement within seven days. Confirmed issues will be assessed, fixed, and disclosed according to their severity and the risk to users.
Security reports may cover the CLI, provider credential handling, command execution boundaries, repository access, release artifacts, and the official website. Third-party model providers and their services remain governed by their own security policies.
Never include real API keys, private source code, or personal data in a report.