Please do not report vulnerabilities through a public issue when they could expose local files, credentials, path authorization, package integrity or update/signing infrastructure.
Send a minimal description to 15179385580@163.com. Do not include API keys, private documents or active exploit material in the first message. You may be asked for a redacted reproduction after receipt is confirmed.
This repository documents public interfaces; the full desktop implementation is maintained separately.