Do not open a public issue for a security problem. Use GitHub's private report instead:
- Go to https://github.com/antick/loadout/security/advisories/new.
- Say what you found, the version (Settings → About), your system, and the steps to reproduce it.
You get an answer as soon as it can be looked at. A fix ships in the next release, and the report is published once people have had time to update.
Loadout runs on your computer and acts on files you own. These are the areas that matter most:
- Writing, replacing or deleting anything outside the library, or outside a folder Loadout put in an agent or project.
- Installing a skill, archive or update from a source other than the one you chose.
- Keys, tokens or passwords ending up in a backup, a log, an export or a shared preset.
- The app's own update: a download that is not checked against the release checksum.
Only the latest release gets fixes. The app updates itself, so update first.