If you discover a security issue in Memorium, report it privately to the repository owner before opening a public issue.
Include:
- a short description of the issue
- the affected files or feature area
- reproduction steps
- any suggested remediation
Security-sensitive areas in this repository include:
- local environment variables and API keys
- desktop permissions for screen capture, microphone, accessibility, and input monitoring
- local database and captured media handling
- dependency updates for the Python, Node, and Rust portions of the project