# Security Policy ## Scope This package is a local DSH host plugin. It classifies recent request text and delegates the request to a model on a provider route already configured by the user. ## Data and credentials The package does not contain API keys, read credential files, call remote endpoints directly, run commands, install dependencies, or send telemetry. The target LLM provider receives the request through DSH's normal LLM seam. ## Reporting Please report security issues privately to the repository owner before opening a public issue. Include the package version, DSH version, Node.js version, and a minimal reproduction. Do not include API keys or conversation secrets.