Security policy
July 27, 2026 ยท View on GitHub
VibeMeter reads sensitive local development metadata. Privacy, retention, Hook-integrity, and export-boundary defects are security issues.
Use the repository's private vulnerability reporting feature. Do not open a public report containing credentials, source code, private prompts, absolute paths, repository identities, databases, or transcripts.
Security-sensitive areas include:
- local session parsing and path sanitization;
- Hook config merge, backup, repair, and uninstall;
- Unix socket permissions and payload bounds;
- 90-day raw live-event retention;
- secret detection and Share Guard;
- provider authentication reuse;
- read-only source handling.
Reports should include the affected version, a minimal synthetic reproduction, expected behavior, and observed impact.