Security reports are relevant to the local companion, loopback WebSocket bridge, MessagePack decoder, MCP input validation, and Figma Bridge plugin.
Do not disclose a suspected vulnerability in a public issue. After the repository is published, use GitHub's private security advisory flow for this repository and include:
- a concise impact assessment;
- reproduction steps or a minimal proof of concept;
- affected version or commit;
- a proposed mitigation if one is known.
Please allow maintainers reasonable time to investigate and release a fix before public disclosure.