If you discover a security vulnerability in anvil:
- Do NOT open a public GitHub issue
- Email: ugurcan.aytar@gmail.com
- Include: description, steps to reproduce, potential impact
- Acknowledgment: within 48 hours
- Assessment: within 1 week
- Fix: depends on severity, typically within 2 weeks
- API key leakage (keys in wiki pages, logs, error messages)
- Path traversal (accessing files outside project directory)
- Command injection (via source filenames, wiki page names)
- LLM prompt injection through source content