Skip to content

Security: mauromedda/ccctx

Security

SECURITY.md

Security

ccctx manages Claude Code and pi Anthropic OAuth session state. Treat profile snapshots, credentials, and tokens as sensitive.

Reporting

Please report vulnerabilities privately to the maintainer before opening a public issue. Include reproduction steps, affected platforms, and any relevant commit hash. Do not include real tokens or credential payloads.

Sensitive Data

Do not attach:

  • .credentials.json
  • full .claude.json files
  • pi auth.json files
  • ~/.ccctx profile directories
  • OAuth access or refresh tokens
  • macOS Keychain exports

Use synthetic configs in bug reports and tests.

There aren't any published security advisories