Security fixes currently target the latest commit on main.
Use GitHub Private Vulnerability Reporting for this repository. Do not publish credential exposure, unsafe process execution, path handling, or privacy issues in a public issue before the maintainer has reviewed them.
Include the affected version or commit, reproduction steps, expected and observed behavior, impact, and redacted evidence.
TokPace executes a user-selected or locally discovered Tokscale binary and stores limited quota history. Executable-path substitution, unintended network behavior, persisted personal data, raw JSON retention, package integrity, and launch-at-login behavior are in scope.