Security fixes target the latest GitHub release and current master. Older
releases may not receive backports.
Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting.
Include the affected version or commit, Claude Code and Python versions, impact, and a minimal sanitized reproduction. Do not attach real analytics logs: session identifiers and private skill names may be sensitive.
Reports involving unintended content capture, data transmission, unsafe log paths, command injection, or disclosure across projects are especially useful.