Report a vulnerability through GitHub's private vulnerability reporting on this repository. Do not open a public issue.
In scope: the SessionStart hook, tools/, and the scripts shipped under plugins/pstack/skills/. The plugin has no server and no telemetry.