Please report suspected vulnerabilities privately through GitHub's security-advisory reporting for this repository.
Do not include credentials, private provider payloads, local database contents or personal file paths in a public issue.
ModelBar should never store provider credentials, open Hermes databases for writing, or load third-party provider code at runtime. A report that shows any of those behaviours is security-sensitive.