Threadsmith is a local-first workflow deck. Please do not file security issues with secrets, tokens, or credential material pasted into public issues.
If you believe you found a security issue, please avoid opening a public issue with sensitive details. Prefer a private disclosure channel if available, or contact the maintainers directly through the repository owner.
- Do not include API keys, tokens, password files, or private
.threadsmithruntime artifacts in public reports. - Public bug reports should use the smallest possible reproduction.