Skip to content

Security: Tyr9102/project-map

SECURITY.md

Security

Project Map runs a local web server, and a note sent from the map page wakes your Claude Code session with that note's text. So security reports are taken seriously - especially anything that lets another website, another program or another account put words in front of Claude, or read or change your maps.

Please report vulnerabilities privately, not in a public issue: use Report a vulnerability on GitHub. Include the steps to reproduce, your operating system and browser. You'll get a reply within a week.

What the plugin protects against, and what it does not, is described in Security model.

Only the latest version on main is supported.

There aren't any published security advisories