Security fixes target the default branch and, when practical, the latest
published release. The 0.2.0 release candidate is not yet published; older
releases receive fixes on a best-effort basis.
Please report vulnerabilities privately through
GitHub's private vulnerability form.
If that form is unavailable, email Lenvanderhof@ReasonKit.sh with the subject
ReasonKit Think security report.
Include the affected version or commit, impact, reproduction steps, and a minimal proof of concept. Redact credentials, personal data, and unrelated machine details. Do not disclose the report in a GitHub issue or discussion before a fix is coordinated.
The maintainers will acknowledge the report, attempt to reproduce it, assess affected versions, and coordinate remediation and disclosure. Response times depend on severity and maintainer availability; no fixed SLA is promised.
Relevant reports include MCP framing or schema bypasses, fail-open governance, unsafe local-state handling, command execution, credential exposure, and dependency vulnerabilities. Ordinary disagreement with a heuristic score is a quality issue unless it also crosses a documented security or policy boundary.