If you find a security issue in Eniac, please report it privately before creating a public issue.
Preferred reporting path:
- Open a private security advisory on GitHub if the repository supports it.
- If private advisories are unavailable, contact the maintainers through ParamissionLab.
Please include:
- A clear description of the issue.
- Steps to reproduce or the affected file and section.
- The expected impact.
- Any suggested mitigation, if known.
Security issues may include:
- Instructions that could cause unsafe command execution.
- Guidance that could encourage leaking secrets, credentials, private files, or sensitive user data.
- Prompt patterns that could bypass user intent, scope boundaries, or approval requirements.
- Documentation that misrepresents supported behavior in a way that creates operational risk.
- Installation or update instructions that overwrite user data unexpectedly.
Maintainers will review reports, determine impact, and publish a fix or mitigation when appropriate. Public disclosure should wait until a fix or documented mitigation is available.