ChatMark reads local Codex and Claude Code transcripts. It has no network service, telemetry, API keys, or third-party package dependencies. It does not execute transcript text; the preview displays plain Markdown text.
- Exported Markdown is plaintext and retains secrets or personal information present in visible messages. Filtering tool output and instructions is not secret redaction.
- Session titles and export filenames can reveal conversation topics. Watched-session metadata in local UserDefaults includes source/output paths, titles, and project names.
- Diagnostics may include local filesystem paths and errors.
--diagnose --export-toexports actual conversations.--ui-smoke-testcreates actual conversation exports and a preview screenshot. - Files in a shared or cloud-synced folder may be accessible to other people or services. Clipboard managers may retain copied Markdown.
Keep exports outside the source repository. Share only synthetic reproductions, and inspect screenshots and logs before attaching them to issues.
For a vulnerability, use the repository's Security → Report a vulnerability option if the maintainer has enabled private reporting. If that option is unavailable, open an issue asking for a private reporting channel without including exploit details, credentials, or personal data. Do not attach real transcripts.
Review the exact files and Git history that will be published. .gitignore prevents some accidental additions; it does not remove tracked files, scrub history, or detect secrets in arbitrary Markdown files.
- Inspect
git status --short --untracked-files=all,git ls-files, and the staged diff. Exclude transcripts, exports, smoke-test screenshots, diagnostic logs, credentials, and generated bundles or caches. - Review all branches and tags being published, including previous file contents, commit messages, and author/committer email addresses. Use your hosting account's verified no-reply address for future commits if you want to keep your email private; changing Git configuration does not change existing commits.
- If sensitive content was committed, removing the current file is insufficient. Revoke exposed credentials, and resolve the affected history before publication. A reviewed source-only snapshot in a new repository avoids publishing old Git metadata; making the original repository public still exposes its original history.
- Check the hosting service separately for issues, pull requests, release attachments, workflow logs/artifacts, and other uploaded content. A local checkout does not contain everything the host may make public.
- Publish only reviewed source files. Enable private vulnerability reporting and available secret-scanning/push-protection features on the host.
A local source review and pattern scan reduce exposure risk but cannot guarantee the absence of all secrets or vulnerabilities.