ContextClaw takes vulnerability reports seriously.
Please do not open public GitHub issues for suspected vulnerabilities. Send reports to:
Helpful reports include:
- affected version, release, or commit;
- impact and affected component;
- reproduction steps or proof of concept;
- relevant environment details;
- suggested fix or mitigation, if available.
The supported public version is the current master branch and latest release only, unless another support window is documented.
The project aims to acknowledge security reports within 7 days and provide a triage update within 30 days when possible.
ContextClaw supports coordinated disclosure. Reporter credit is available by request, unless legal, safety, or privacy constraints prevent it.