Security fixes land on the latest minor line only.
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
| 0.0.x and older | ❌ — upgrade with lzy update (pre-0.0.7 installs use the manual two-step documented in the README) |
Please use GitHub's private vulnerability reporting (the repository's Security tab → "Report a vulnerability") so details stay out of public view. Do not open a public issue for anything exploit-shaped.
Where relevant, include:
- Your
lazyzcodeversion (lzy --version) and platform (macOS / Windows / Linux, arch) - The ZCode desktop engine version involved
- Steps to reproduce and the impact you observed
lzy doctoroutput if the report involves hook execution or the CLI
The maintainer aims to acknowledge reports within 7 days and will keep you informed of the fix and disclosure timeline. Fixes ship in a patch release; credit in the changelog is yours unless you prefer otherwise.
In scope
- Code in this repository (
cli/,core/,plugin/) and the published npm packagelazyzcode - The marketplace manifest (
.claude-plugin/marketplace.json) and everything the install/sync flow writes or executes - Injection, path traversal, or state corruption in the goal-loop state under
.lazyzcode/
Out of scope
- The ZCode engine and desktop app themselves — report those upstream
- Issues that require physical access to the machine or social engineering
- The behavior or output of the models behind the engine
What this project promises about its own security surface:
- Zero telemetry. Nothing leaves your machine; diagnostics are computed
and printed locally by
lzy doctor. config.jsonis never written. Install = plugin cache placement + registry write; enable = the engine's officialplugins enable(ADR-0001).- Hooks fail open. A missing or broken hook environment degrades the discipline layer, never the host session.
- All state is local, under
.lazyzcode/and the ZCode plugin cache. Two declared exceptions (M2, a1.r3 F-3 / a1.r13 F-5): the review sandbox usage ledger appends one line per paid review run to the user-private~/.zcode/cli/lzy-usage/YYYY-MM.jsonl(0600, local only, records project path + provider/model token usage), and--workerswave orchestration creates sibling worktrees next to the host repo as<sibling-dir>/<repo>-fast/. Both are user-local, never synced or transmitted. - Spawn sites use literal argv with
shell: false, including the Windowscmdpaths, which go throughComSpec /d /s /cwith literal strings. The hook launcher failure log lives in the user-private profile (~/.cache/lzy-hook/,%APPDATA%\lzy-hook\) — no world-writable shared-directory write points.
These properties are contract-tested. If you find a violation, that is a security-relevant report — please follow the private reporting channel above.