This project is currently alpha. Security fixes are handled on the main development line.
Please report security issues privately to the maintainer before public disclosure.
If no private security contact is configured on GitHub yet, open a minimal issue asking for a private reporting channel without disclosing exploit details.
The engine is local-first. It does not upload source code by default.
Future remote embedding or hosted integrations must document what leaves the machine and require explicit opt-in.