Please report security issues privately through GitHub: Report a vulnerability (the repository's Security tab). Don't open a public issue or pull request for a suspected vulnerability.
Include what you found, how to reproduce it, and the impact you expect. We'll acknowledge the report and keep you updated as we investigate.
- Never commit API keys. Keys live in
.env.<org>files, which are gitignored, or in CI secrets. The tools never accept a key as a command-line flag, so it can't leak into shell history. - Committed state contains IDs, not secrets.
.vapi-state.<org>.jsonmaps resource names to Vapi UUIDs. Credential secrets and phone-number provisioning are never written to the repository. .tsresource files run code. Loading a TypeScript resource executes its module, including invalidate,promoteplans and PR checks. Review them like code, and only run them from trusted branches.- PR checks run with your key on same-repository branches. Forked PRs get a dry run with no secrets. See "Cost and safety" in docs/guides/pr-checks.md for what a check still sends to real providers.