This project is under active development. Security fixes are applied on the latest mainline version.
If you discover a security issue:
- Do not open a public issue with exploit details.
- Contact maintainers privately with:
- impact summary
- reproduction steps
- affected files/versions
- Allow reasonable time for triage and patching before public disclosure.
Typical security-sensitive areas:
- secret/config handling (
backend/data/config.json,.env) - runtime logs/sessions under
backend/data/agents/ - tool execution and path validation