Security reports can include private Yarn scripts, local MCP credentials or update/install behavior. Do not post a working exploit, token, private project data or vulnerable user path in a public issue.
For a suspected vulnerability, use GitHub private vulnerability reporting when available, or email ryuumeow@synapsecore.net with Spindle security in the subject. Include the affected version, Windows/Web environment, reproduction steps, expected impact and a safe proof of concept. If a credential may have been exposed, reset it in Settings → MCP / Agent integration and update installed agent connections.
The latest public release receives priority for security fixes. Older builds may require an upgrade. No fixed response or disclosure deadline is promised; coordinated disclosure will be arranged with the reporter when a finding is confirmed. Ordinary bugs and feature requests belong in Issues.