Security fixes are provided for the latest published minor release of Tinker.
Do not open a public issue for a suspected vulnerability. Use GitHub private vulnerability reporting and include reproduction steps, affected versions, and the potential impact.
You should receive an acknowledgement within seven days. A fix and disclosure plan will be coordinated privately before an advisory is published.
Tinker can read and modify files, start subprocesses, and send selected content to a configured model provider. Users are responsible for reviewing workspace permissions, provider data policies, project instructions, skills, and MCP server configurations before using Tinker with sensitive material.