Cycles Budget Guard runs in Claude Code's tool-dispatch path. Please report suspected enforcement bypasses, incorrect charging, credential exposure, or supply-chain vulnerabilities privately.
The latest published release receives security fixes. Older pre-1.0 releases are unsupported once a replacement is available.
Use GitHub private vulnerability reporting. Do not open a public issue for a suspected vulnerability.
Include the plugin, Claude Code, Node.js, and operating-system versions; a minimal reproduction; the expected enforcement decision; and the observed result. Redact API keys, tenant/application identifiers, prompts, file contents, and tool arguments.
Do not test against infrastructure or budgets you do not own or administer. We will coordinate validation, remediation, and disclosure through the private advisory.