# Security & Safety Policy

## 🛡️ Our Commitment
We take the security of our users and the integrity of the AI-CLI-PRO community as our highest priority. We are committed to a transparent, fast, and responsible disclosure process.

---

## 📞 Reporting a Security Vulnerability
If you discover a security vulnerability in AI CLI PRO, please report it privately whenever possible.

### 🔐 Private Reporting
Please use GitHub's private security reporting / Security Advisories feature when available. When reporting privately, do not publish exploit details or sensitive data in public issues.

Do not publicly disclose:

- API keys or authentication credentials
- OAuth tokens or session tokens
- Private user data
- Exploitable vulnerability details
- Proof-of-concept code that could enable exploitation
- Sensitive logs or configuration files

If private reporting is unavailable, open a minimal GitHub Issue without including secrets or sensitive exploit details and request a private follow-up.

### Please include

- A clear description of the vulnerability.
- The affected component or feature.
- Potential security impact.
- Steps to reproduce, where safe to provide (redact secrets).
- Relevant version/commit information.
- Screenshots or a sanitized proof of concept, if appropriate.

Please redact credentials, tokens, personal information, private source code, and other sensitive material before submitting a report.

### Response Process

1. **Triage:** We will acknowledge your report and, where possible, confirm receipt within 24-48 hours.
2. **Investigation:** We will reproduce and investigate the reported issue.
3. **Resolution:** We will develop and test an appropriate fix.
4. **Disclosure:** After a fix is available, we may coordinate responsible disclosure and a public advisory where appropriate.

---

## 📋 Community Moderation
For issues related to harassment, spam, or violations of our [Code of Conduct](CODE_OF_CONDUCT.md), please use the same issue tracker with the `moderation` label.

**Thank you for helping us build a safer future for AI-powered development! 🤝**
