If you discover a vulnerability, please do not open a public issue with exploit details.
For now, report security issues by opening a GitHub issue with a minimal description and marking it clearly as security-sensitive. The maintainer will coordinate a private follow-up channel if needed.
Security-sensitive areas include:
- WorkBuddy local session reading
- Status plugin installation
- Hook event projection
- Local spool file permissions
- macOS packaging and signing
如果你发现安全问题,请不要在公开 issue 中贴出可复现攻击细节。可以先开一个简短 issue,说明这是安全相关问题,维护者会进一步沟通。