SECURITY.md
SECURITY.md
Only the latest published revision is supported.
Do not publish mailbox credentials, app passwords, raw private email, or exploitable details in a public issue. Contact the fork maintainer privately through the contact method shown on the LM Studio Hub or repository profile.
Include:
Revoke affected app passwords immediately if credential exposure is suspected.
The plugin assumes:
The plugin therefore disables write tools by default and labels retrieved email as untrusted. Host-level tool approval remains strongly recommended whenever write tools are enabled.
This plugin is not a secure email gateway, malware scanner, data-loss-prevention system, or OAuth credential broker. It does not inspect attachment contents. Moving a message to Trash is not guaranteed to be reversible indefinitely because provider retention policies differ.
Only the latest published revision is supported.
Do not publish mailbox credentials, app passwords, raw private email, or exploitable details in a public issue. Contact the fork maintainer privately through the contact method shown on the LM Studio Hub or repository profile.
Include:
Revoke affected app passwords immediately if credential exposure is suspected.
The plugin assumes:
The plugin therefore disables write tools by default and labels retrieved email as untrusted. Host-level tool approval remains strongly recommended whenever write tools are enabled.
This plugin is not a secure email gateway, malware scanner, data-loss-prevention system, or OAuth credential broker. It does not inspect attachment contents. Moving a message to Trash is not guaranteed to be reversible indefinitely because provider retention policies differ.