AIHelper provides security updates for the latest published GitHub Release. Older versions are not supported and may be asked to reproduce an issue on the latest release.
Report vulnerabilities through GitHub Private Vulnerability Reporting. This gives the maintainer and reporter a private place to investigate and coordinate disclosure.
Do not disclose vulnerability details in a public issue, discussion, pull request, or other public channel.
Include as much of the following as possible:
- the affected AIHelper version;
- operating system and architecture;
- installation source;
- the affected CLI, MCP, plugin, packaging, or updater surface;
- expected impact;
- reproduction steps or a minimal proof of concept;
- sanitized logs or diagnostics;
- any suggested mitigation.
Remove access tokens, credentials, signing material, personal data, and other secrets before submitting a report.
Reports will be reviewed privately and coordinated disclosure will be discussed with the reporter. The project does not currently promise a response or fix SLA, a bug bounty, or a specific disclosure timeline.