Report vulnerabilities privately to security@openrouter.ai. Do not report them in Discord or any public channel.
Include the following when possible.
- A description of the vulnerability
- Steps to reproduce
- The affected version or commit
- The possible impact
- Any suggested fix or mitigation
We will acknowledge your report and follow up.
Send feedback and bug reports to #ori in OpenRouter's Discord rather than GitHub.
This policy covers the released ori CLI and the release assets distributed from this repository.