This project accepts source text and, when explicitly requested, sends a process description to a configured LLM provider. The core linter, Markdown handling, and offline synthesizer do not require network access or optional model packages.
Report suspected vulnerabilities through the private security-advisory mechanism provided by the repository hosting the project. Do not include API keys, access tokens, private customer data, or unreleased source code in a report. If private reporting is unavailable, contact the maintainers through the channel documented by the hosting organization.
Do not open a public issue containing exploit details or sensitive data.
- Use a dedicated, least-privilege API key for LLM experiments and rotate it after use.
- Review the selected provider's retention, training, and transport policies before sending descriptions.
- Keep
.envfiles out of version control. The repository ignores.envand its variants while retaining.env.example. - Treat generated Mermaid as untrusted text. A diagram source is not a safe HTML or script policy mechanism.
- Review repairs before writing them into production documentation. The tool preserves uncertain input and reports failures, but users remain responsible for the final source.
- Use
--forceonly when replacing the selected output is intentional. The CLI rejects symbolic-link output paths and uses atomic replacement for regular files. - Keep input size limits enabled when processing files from untrusted locations.
The latest released version is the supported line. Security fixes are applied to the current release line unless a project release note states otherwise.