Security fixes are provided for the latest release tagged on GitHub Releases. Pin installs to a release tag rather than an unverified main checkout.
Preferred: Use GitHub Private Vulnerability Reporting for this repository.
Fallback: Email tizerluo@gmail.com with a description, reproduction steps, and impact assessment. Expect a response within 7 business days.
Please do not open public issues for undisclosed security vulnerabilities.
This policy covers the oh-my-cursor MAP engine (hooks, install tooling, skills, and tests). Consumer-project code installed via --project is out of scope unless the vulnerability is in oh-my-cursor itself.
MAP merge-gate markers rely on a local HMAC secret. See docs/security.md for the trust contract and run python3 scripts/install.py --doctor --security after install.