| Version | Supported |
|---|---|
| latest | Yes |
If you discover a security vulnerability, please report it responsibly:
- Do not open a public issue
- Email: [security contact via GitHub]
- Include: description, reproduction steps, and impact assessment
- Command injection via tool arguments
- API key exposure or leakage
- Unauthorized Stripe API access beyond declared tool capabilities
- Path traversal in file operations
- Third-party dependency vulnerabilities (report upstream)
- Denial of service attacks
- Issues requiring physical access