Security policy

Report sensitive failures privately.

Do not open a public issue for credential exposure, chat-boundary bypasses or donation-deletion failures.

Private contact

Email security@openqueries.org or use a private GitHub security advisory. Include a minimal synthetic reproduction and the affected extension or API version.

High-priority reports

  • Extraction of chat messages or conversation metadata.
  • Provider credentials present in an extension bundle or log.
  • Cross-installation deletion or quota bypasses.
  • A tombstoned donation being stored after deletion.
  • Sensitive-query filters that can be bypassed.

Safe reporting

Never attach real chats, credentials or personal information. We will acknowledge valid reports and coordinate remediation before public disclosure.