Please use GitHub's private vulnerability reporting for suspected security issues. Do not open a public issue containing credentials, host addresses, pairing material, exploit details, or personal data.
Include the affected version, impact, reproduction steps, and any suggested mitigation. Reports will be acknowledged and assessed before coordinated disclosure.
SlopLink is a remote client for infrastructure operated by its user. Operators are responsible for host authentication, HTTPS, network exposure, updates, and access control. SlopLink stores pairing credentials in the device-only Keychain and does not accept cloud-provider credentials.