| Version | Supported |
|---|---|
| 1.0.x | Yes |
| < 1.0 | No |
If you discover a security vulnerability, please report it responsibly:
- Do not open a public issue
- Email parthalon025@gmail.com with:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- You will receive a response within 48 hours
This toolkit executes shell commands as part of its quality gate pipeline. Security considerations:
evalusage: PRD acceptance criteria useevalto run shell commands. Only run PRDs you trust.- Headless execution:
run-plan.shexecutesclaude -pwith plan content. Only run plans from trusted sources. - Ollama integration:
auto-compound.shsends report content to a local Ollama instance. No data leaves your machine. - Telegram notifications: Optional. Credentials read from
~/.env. Never logged or committed.