If you discover a security vulnerability in this plugin, please report it by opening a GitHub issue.
Since this is a local-only desktop plugin with no network services or authentication, the attack surface is minimal. However, all reports are taken seriously and will be addressed promptly.