Security fixes are made on the latest published release and the main branch.
Please use GitHub's private vulnerability reporting flow under Security → Advisories → Report a vulnerability. Do not open a public issue for a suspected vulnerability.
Include the affected interface (library, CLI, MCP server, bookmarklet, or web demo), reproduction steps, impact, and any suggested mitigation. You can expect an acknowledgement within seven days.
- The published generator has no runtime dependencies and does not make network requests.
- The web demo processes text locally. Export, history, and permalink features do not send generated text to an application server.
- The bookmarklet intentionally changes text in the page where a user runs it; it should only be used on pages the user trusts.
- HTML output escapes generated content. Please report any path that can introduce unescaped user-controlled markup.