# Security Policy
## Reporting
Report vulnerabilities through GitHub Security Advisories for this repository when available. If that is not available, open a minimal public issue asking for a private security contact and avoid posting exploit details.
Do not include tokens, private prompts, `.env`, `.npmrc`, or `~/.practicode` contents in public reports.
## Scope
Security-sensitive areas include npm install scripts, release publishing, command execution, local judging, AI provider prompts, update checks, and local user data handling.