Only the latest release is supported.
Please use GitHub's private vulnerability reporting — do not open a public issue for security problems. Reports are appreciated even when you are unsure whether something counts as a vulnerability.
- This repository — the VS Code extension: webview UI, engine process
management, local IPC. The extension talks to the engine on
127.0.0.1only, generates a per-process Runtime token that stays out of command arguments, settings and logs, and contains no telemetry or analytics. - The agent engine (
codewhaleCLI — model traffic, tools, sandboxing, prompts) is a separate project. Report engine vulnerabilities to Hmbown/CodeWhale, not here.