Please report security issues privately, not in a public issue.
Use GitHub's Report a vulnerability button (Security → Advisories) to open a private report. You will get an acknowledgement within a few days.
This tool reads the Anthropic OAuth usage API with a token stored on the local machine. When reporting, please note anything touching:
- how the OAuth token is read, stored, or logged;
- the tray process running with unexpected privileges;
- any network call to a host other than the Anthropic API.
Please do not include a real token in your report — redact it.
Only the latest release on main receives fixes.