- Memory system (mcp-server.py, chroma-helper.py)
- Install scripts (install.ps1, install.sh)
- MCP server protocol implementation
- Skill content (factual errors, broken references)
- Out of scope: Configuration files with user-specific paths
If you find a security vulnerability (exposed API keys, credentials in the repo, etc.):
- Do not open a public issue
- Email elias@cyberian.online directly
- PGP Key: not yet available. For sensitive reports, request the key at the same email.
- Include a description of the issue and steps to reproduce
We will respond within 48 hours and work on a fix before public disclosure.
We ask that you give us reasonable time to address any security issue before sharing it publicly.