Security fixes target the latest main.
Report vulnerabilities privately: roger@tres65.es.
Include:
- Issue summary.
- Repro steps or proof of concept.
- Affected file, skill, command, or generated artifact behavior.
- Impact and known workaround.
Do not open a public issue until the report has been reviewed.
High-value areas:
- Script injection in generated HTML.
- Unsafe SVG/icon handling.
- Unexpected external runtime loading.
- Feedback import parsing.
- Prompt export leaking hidden context.