Files
oai-swift/SECURITY.md
T

1.3 KiB

Security Policy

Supported Versions

Only the latest publicly released version of oAI is supported with security fixes. Please update to the latest version before reporting an issue, and confirm it still reproduces there.

Reporting a Vulnerability

If you discover a security vulnerability in oAI, please report it privately rather than opening a public GitHub issue.

To report a security concern, use the contact form at https://oai.pm/#contact.

Please include as much detail as possible:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce the issue
  • The oAI version and macOS version you're using
  • Any relevant logs (~/Library/Logs/oAI.log), with sensitive data redacted

Scope

oAI is a native macOS app that stores conversations, settings, and API keys locally (SQLite database and Keychain). Areas of particular interest for security reports include:

  • API key handling and Keychain storage
  • MCP file access permission checks
  • Bash execution approval flow
  • Any path that could lead to data exfiltration or unauthorized local file/system access

Response

Reports submitted through the contact form will be reviewed and acknowledged as soon as possible. Please allow time for a fix to be developed and released before any public disclosure.