Only the latest version on the main branch is supported with security updates.
| Version | Supported |
|---|---|
| main | ✅ |
Please do NOT open a public issue for security vulnerabilities.
Instead, report vulnerabilities by emailing helix2066@gmail.com directly.
Please include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
You will receive an acknowledgment within 72 hours of your report.
The following are considered security issues for this project:
- Bypass of
pre-bash-safety.shdestructive command blocking - Bypass of
pre-write-safety.shorpre-edit-safety.shsensitive file protection - Path traversal in hook scripts
- Unintended command execution through hook inputs
- Issues in Claude Code itself — please report to Anthropic
- Issues in user-configured CLAUDE.md or custom settings