If you discover a security vulnerability in sci-plot, please report it responsibly.
Email: 17538703215@163.com
Please include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fixes (optional)
- Initial response: Within 72 hours
- Status update: Within 1 week
- Fix timeline: Depends on severity (critical issues prioritized)
sci-plot is a prompt generation tool that:
- Does not generate images directly
- Does not connect to external services
- Does not handle sensitive data
Security concerns typically relate to:
- Prompt injection vulnerabilities
- File path traversal in content analysis
- Malicious content in generated prompts
- Always review generated prompts before using them
- Do not use sci-plot to analyze untrusted or malicious files
- Be cautious when pasting prompts into external image generation services
| Version | Supported |
|---|---|
| 1.1.x | ✅ |
| 1.0.x | ✅ |
| < 1.0 | ❌ |
- Vulnerabilities will be disclosed publicly after a fix is released
- Reporter will be credited (unless anonymity is requested)
- Security advisories will be published on GitHub