Please report security issues privately through GitHub's Report a vulnerability flow for this repository. Do not open a public issue containing device identifiers, local paths, command output, or exploit details.
Include the affected Omapoint commit, Omarchy version, Solaar version, and a minimal reproduction when available. Redact hardware unit IDs, Bluetooth addresses, usernames, and other machine-specific values.
Omapoint runs unsandboxed inside Omarchy Shell and can launch locally configured commands. A report should distinguish behavior from an explicitly configured action from an authorization or validation bypass.