This policy covers the MacClaw macOS desktop app.
Please report vulnerabilities privately to project maintainers.
When reporting, include:
- affected version/commit
- reproduction steps
- impact assessment
- optional fix suggestion
Do not publish proof-of-concept exploits publicly before maintainers confirm and patch.
- Never commit real gateway tokens/passwords.
- Never paste credentials in issues or logs.