Use GitHub private vulnerability reporting to report a security issue. Do not disclose vulnerabilities in public issues.
Include the plugin version, CLI version, affected operation, and a minimal reproduction. Use sanitized setup output. Do not include API keys, OAuth files, or raw Kimi configuration.
The safety boundary spans these components:
runtime/hooks/verifies the installed hook, controls config writes, and checks tool callsruntime/rescue-approval.tschecks write paths, shell arguments, and the trusted workspace rootruntime/kimi-engine.tsselects certified versions and records engine provenanceruntime/native-v2-preflight.tsblocks plan mode, unsafe experimental features, and unsafe resume stateruntime/cli-client.tschecks the spawned engine and tears down subprocesses
Read the safety guide and runtime contracts before changing these components. The hook controls tool use; it is not an operating-system sandbox.