If you find a security issue (for example, a way a filter or the hook rewriter could execute unintended code, leak data, or bypass the "never break a command" guarantee), please do not open a public issue.
Instead, report it privately using GitHub's private vulnerability reporting, or email security@pyxel.dev.
Please include:
- A description of the issue and its potential impact
- Steps to reproduce, or a minimal example
- Any relevant version/commit information
We'll acknowledge reports as soon as possible and keep you updated as the issue is investigated and fixed.