m6t runs with the user's own credentials (kubeconfig, SSH keys, git credential helpers) and executes local binaries on their behalf. Vulnerabilities in the loopback stream server, the exec wrappers, or credential handling are taken seriously.
Please do not open a public issue. Report privately via GitHub security advisories or email cjimti@gmail.com with a description and reproduction steps.
You will get an acknowledgment within a few days. Please allow a reasonable window for a fix before public disclosure.
Pre-release: only the latest main is supported.