This repository holds only the installer, the launcher and documentation for Command Code. It contains no Command Code source code. Vulnerabilities in Command Code itself should be reported to its authors according to their own policy — not here.
scripts/install.sh,scripts/uninstall.sh,scripts/finish-cmdcode.shorbin/cmdcodedoing something destructive or unsafe on a device: deleting a file it does not own, writing world-readable secrets, running commands from untrusted input, or bypassing its own validation.- A credential, private key, personal path, host identifier or LAN address committed to this repository.
- A documented command or flag that does not exist, or an installer that claims a check it does not perform.
- Failure to install Command Code, or errors originating in Command Code.
- Anything you configured locally in
~/.commandcode/, which lives outside this repository. Its permissions are Command Code's concern. - Running Command Code with
--yoloor--permission-mode accept-edits. That is your choice; the launcher does not add permissions of its own.
Report privately through GitHub's security advisory form for this repository (https://github.com/XtrComSu/command-code-termux/security/advisories/new). Please include:
- what you ran, on which Termux and Node.js version,
- what you expected and what happened instead,
- the relevant script and line.
Please do not open a public issue for an unfixed vulnerability, and do not include real API keys, tokens or personal data in the report — redact them.
You can expect an acknowledgement within a few days. Fixes land in a normal commit history; if a report turns out to affect installed devices, the advisory will say so.
If you are unsure whether an installation is intact:
grep -n "npm install" scripts/install.sh # one pinned call, no hidden fetches
./tests/run-tests.sh # includes a secret scan of the tree
cmdcode info # shows what the CLI actually loadedThe installer never writes credentials anywhere, and never fetches anything other than the pinned npm package.