Please report security vulnerabilities privately. Do not open a public issue, pull request, or discussion for a suspected vulnerability.
Preferred: use GitHub’s private vulnerability reporting on this repository — the Security tab → Report a vulnerability. This opens a private advisory visible only to the maintainers. (Maintainers: enable this under Settings → Code security and analysis → Private vulnerability reporting.)
Alternative: email the maintainers at seth@sjseth.com.
Please include as much as you can:
This policy covers the desktop application in this repository. The hardware/firmware, the local model server, and the hosted community backend are separate projects — report issues in those to their respective maintainers.
A few things worth knowing about how the app handles content from others:
weights_only=True and warns before importing or downloading a model, but you
should still only load models from sources you trust.