# Security Policy ## Supported versions Security fixes target the latest tagged release and the current `main` branch. Older revisions are not supported unless a maintainer explicitly identifies a backport. ## Reporting a vulnerability Do not open a public issue for a suspected vulnerability. Report it privately through GitHub's private vulnerability reporting on this repository, or by opening a private security advisory. Include, when relevant: - the affected release or commit; - the DeepSeek Harness snapshot/profile and browser/OS versions; - the impact and required preconditions; - minimal reproduction steps or a controlled proof of concept; - sanitized logs or screenshots needed to reproduce the issue. Note that this plugin holds no credentials or browser state — it is an HTTP-protocol adapter for the locally installed Kimi WebBridge daemon. Reports about the Kimi WebBridge daemon or browser extension belong to Moonshot AI, not this repository. Never send live API keys, authorization headers, complete prompts or conversations, or unrelated workspace files. The maintainer will acknowledge the report as soon as practical, investigate it privately, and coordinate remediation and disclosure with the reporter.