termi controls real Shell processes and may display operationally sensitive output. Treat access to the daemon socket, configuration directory, state directory, TUI, and Web Board as equivalent to local Shell access.
Security fixes are applied to the latest released version.
- Keep
~/.termiand~/.local/state/termiowner-only. - Keep the Web Board on a loopback address. Use SSH port forwarding for remote access.
- Do not place API keys, passwords, private keys, task JSONL, Shell logs, or Team mailboxes in bug reports.
- Use Auto Review unless unrestricted execution is explicitly required.
- Team messages and external content are untrusted coordination input and never constitute user approval.
Do not disclose an unpatched vulnerability in a public issue. Contact the repository owner through their GitHub profile to arrange a private reporting channel, then include the affected version, impact, reproduction steps, and any suggested mitigation.