# Security Policy Security fixes are provided for the latest released version of Token Maxxer Hub. Please do not open a public issue for a suspected vulnerability. Use the repository's private vulnerability reporting form (GitHub Security Advisories) so the report can be reviewed privately. Include the plugin version, Omarchy version, reproduction steps, and the security impact. Do not include API keys, account identifiers, or other private data in the report. The plugin runs inside the long-lived `omarchy-shell` process and spawns its bundled Python worker (`ai-hub-worker`, standard library only, no dependencies to audit). Review the source before installation and install only from the repository URL documented in the README. Existing hardening in the worker: - Remote provider requests are restricted to a fixed HTTPS host allowlist; any other host raises an error instead of being contacted. - The user-configurable local-usage endpoint (Antigravity) is restricted to loopback addresses (`127.0.0.1`, `localhost`, `::1`) only. - Remote response bodies are capped in size and fetched with a bounded timeout. - API keys are never passed as command-line arguments, written to state, or logged; they are held only in the system keyring (Secret Service) or an environment variable you manage, and read into memory only for the duration of one outgoing request. - State, cache, and history files are written atomically with owner-only permissions. - SQLite databases belonging to other local tools (OpenCode, Cursor) are opened strictly read-only. If you find a way around any of the above, that's exactly what the private reporting form is for.