Security fixes are handled on the main branch.
Please do not publicly post API keys, transcripts, audio recordings, or exploit details in an issue.
If you find a security problem:
- Open a minimal issue that says a security report is available, without secrets or exploit details.
- Contact the repository owner through GitHub profile information.
- Include reproduction steps, affected files, and impact when sharing details privately.
This project can process microphone audio, speaker audio, transcripts, and API credentials. Contributors should avoid committing:
.envkeys.py- API keys
- audio recordings
- transcript logs
- generated model files
- screenshots that reveal private conversations
The repository includes secret-scan automation, but contributors are still responsible for checking their changes before opening a pull request.