# Security Policy

Report security issues privately to the maintainer instead of opening a public issue.

Do not include API keys, OAuth tokens, refresh tokens, Hermes config files, or wearable health exports in reports. Describe the affected command, expected behavior, observed behavior, and a minimal reproduction that uses fake credentials.

This package writes local Hermes configuration and skills. Review generated files before sharing logs, and redact paths or values that identify private machines or accounts.
