Email support@doubleagent.so with "security" in the subject for:
- a way to make the CLI leak a secret key, session, private key or credentials file,
- a project file that makes
initwrite outside the project or run code, - a way to make a simulation sign or send telemetry for a site or API it was not given.
Include the package version, a minimal reproduction and what you saw. Do not open a public issue with a working exploit. We will reply, agree on a fix and a disclosure date, and credit you unless you prefer otherwise.
This repository is the command-line tool. Reports about the hosted Double Agent service are welcome at the same address.