Worklings is experimental pre-release software. Security fixes are applied to the latest code on main and, when practical, to the most recent published prerelease. Older alpha builds are not maintained.
Do not open a public issue for a suspected vulnerability or include sensitive details in a public discussion.
Use GitHub's private vulnerability reporting form. Include:
- the affected version or commit;
- steps to reproduce the issue;
- the likely impact;
- any suggested mitigation;
- whether the issue has been disclosed elsewhere.
The maintainer will aim to acknowledge a report within seven days, assess its scope, and coordinate remediation and disclosure with the reporter. Response timing may vary because Worklings is currently maintained as an experimental project.
Reports made in good faith, without accessing other people's data or disrupting services, are welcome. Please allow reasonable time for a fix before public disclosure.
Worklings is local-first and does not intentionally collect prompts, source code, keystrokes, or screen contents. A change that weakens this boundary, exposes local pet state, or requests an unexpected system permission may be security-relevant even when it does not resemble a conventional network vulnerability.