Report vulnerabilities privately to: security@yai.local (placeholder).
Do not publish details before coordinated remediation.
- Intake and initial triage
- Reproduction and impact classification
- Fix and validation
- Coordinated disclosure with advisory/release notes
In scope:
- parsing/input handling in the CLI
- command boundary/authority bypasses
- dangerous mismatches between CLI behavior and specs contracts
No secrets, tokens, or credentials in this repository.