If you discover a security vulnerability, please report it responsibly:
- Do NOT open a public GitHub issue
- Email the maintainer privately or use GitHub's private vulnerability reporting
- Include a description of the vulnerability and steps to reproduce
- We will respond within 48 hours
- Read-only: agent-trace never modifies session files
- Local only: No network requests, no data leaves your machine
- No API keys: No external service dependencies
- No telemetry: No analytics or tracking