Skip to content

Commit b05d88a

Browse files
committed
docs: clarify that malicious config files are not an attack vector
1 parent a3a06ff commit b05d88a

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

SECURITY.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,7 @@ Server mode is opt-in only. When enabled, set `OPENCODE_SERVER_PASSWORD` to requ
2424
| **Sandbox escapes** | The permission system is not a sandbox (see above) |
2525
| **LLM provider data handling** | Data sent to your configured LLM provider is governed by their policies |
2626
| **MCP server behavior** | External MCP servers you configure are outside our trust boundary |
27+
| **Malicious config files** | Users control their own config; modifying it is not an attack vector |
2728

2829
---
2930

0 commit comments

Comments
 (0)