ben10-colorscripts is a small hobby project. It runs entirely under your $HOME — no sudo, no network, no telemetry. So there isn't much attack surface, but if you spot something concerning, I'd still like to hear about it.
Whatever the latest tagged release is. Older tags don't get security backports.
Anything in the installer, the shell block it writes, or the bundled Python code that could execute unintended commands, leak data, or corrupt files outside the project's own directories.
Not in scope: bugs in fastfetch, chafa, python3, or your terminal — report those upstream.
Please use GitHub's private vulnerability reporting instead of opening a public issue. That way we can fix it before details go public.
I'll respond as soon as I can — this is a solo-maintained project, so please be patient beyond a few days if the fix isn't trivial.