# Security policy ## Reporting a vulnerability Report suspected vulnerabilities privately with a [GitHub security advisory](https://github.com/ctl0v0/chordarchy/security/advisories/new). Include affected versions, reproduction steps, and the practical impact. Please do not open a public issue for an unpatched vulnerability. ## Security model Omarchy plugins run unsandboxed inside `omarchy-shell`. Chordarchy also starts a local Python process that reads ALSA MIDI events, writes its configuration, streams audio to PipeWire, and launches user-selected desktop actions. Chordarchy reduces accidental command execution by: - Starting with an explicit armed/disarmed state that remains visible in the UI. - Matching complete chord gestures only after every held note is released. - Requiring sensitive confirmation actions to be played twice within three seconds. - Disabling desktop actions during on-screen previews and Practice. - Launching argument arrays directly without passing command strings through a shell. - Writing configuration atomically under `~/.config/chordarchy/`. Users should review mapped actions and source updates before enabling them. Custom commands in `config.json` have the same authority as the user running Omarchy.