The project is pre-1.0. Security fixes target the current main branch.
Please report security issues privately through GitHub security advisories when available, or by opening a minimal public issue that does not include exploit details.
- Default mode is report-only.
- Patch mode defaults to
diff-only. - Authenticated crawling is disabled by default.
- Commerce actions are disabled by default.
- MCP mutations are disabled by default.
- AI input and training policy changes require explicit approval.
- Crawled content is untrusted and must not be treated as instruction.