Skip to content

Security: ishowshao/tinker

SECURITY.md

Security Policy

Supported versions

Security fixes are provided for the latest published minor release of Tinker.

Reporting a vulnerability

Do not open a public issue for a suspected vulnerability. Use GitHub private vulnerability reporting and include reproduction steps, affected versions, and the potential impact.

You should receive an acknowledgement within seven days. A fix and disclosure plan will be coordinated privately before an advisory is published.

Security model

Tinker can read and modify files, start subprocesses, and send selected content to a configured model provider. Users are responsible for reviewing workspace permissions, provider data policies, project instructions, skills, and MCP server configurations before using Tinker with sensitive material.

There aren't any published security advisories