Security policy

July 27, 2026 ยท View on GitHub

VibeMeter reads sensitive local development metadata. Privacy, retention, Hook-integrity, and export-boundary defects are security issues.

Use the repository's private vulnerability reporting feature. Do not open a public report containing credentials, source code, private prompts, absolute paths, repository identities, databases, or transcripts.

Security-sensitive areas include:

  • local session parsing and path sanitization;
  • Hook config merge, backup, repair, and uninstall;
  • Unix socket permissions and payload bounds;
  • 90-day raw live-event retention;
  • secret detection and Share Guard;
  • provider authentication reuse;
  • read-only source handling.

Reports should include the affected version, a minimal synthetic reproduction, expected behavior, and observed impact.