# Security Policy / 安全策略

## Reporting a vulnerability

Please use the repository's **Security → Report a vulnerability** flow to report security issues privately. Do not disclose credentials, conversation contents, local paths, or exploit details in a public issue. If private vulnerability reporting is unavailable, open a public issue that only requests a private contact channel and contains no sensitive details.

请优先使用仓库的 **Security → Report a vulnerability** 功能私下报告安全问题。不要在公开 Issue 中披露凭据、对话内容、本地路径或利用细节。如果暂时无法使用私密漏洞报告，请只创建一个不含敏感细节的公开 Issue，请求维护者提供私下联系方式。

Include the affected version, operating system, expected impact, and minimal reproduction steps that do not expose private conversation data.

报告中请注明受影响版本、操作系统、预期影响，以及不会泄露私人对话数据的最小复现步骤。
