How to report
Send the details to contato@idyplatform.com or open a private security advisory in the GitHub repository. Do not open a public issue for an unfixed vulnerability.
It helps a lot to include: app version, operating system, steps to reproduce and the impact you observed.
What happens next
We confirm receipt within 5 business days, keep you informed during the fix and agree on a disclosure date. If you want, we credit you in the release notes.
Scope
- The application and the updater.
- The embedded MCP server and the acbridge CLI over a local socket.
- Gate confinement.
- Out of scope: third-party providers and their CLIs.
What Stellar promises
Reading is passive; what creates or destroys asks for consent. Opening a new URL in the canvas browser goes through you. Nothing is downloaded or installed on its own: the updater warns and you click.
What Stellar does not promise
An agent terminal runs with your permissions, without a sandbox. What is confined is the gate: it runs in bubblewrap on Linux and is refused where it does not exist, instead of pretending it confined.
The app is a single writer by design: one process per data directory.
Verifying the package
The macOS .dmg is not signed by Apple. Before opening it, you can check the file’s sha512 hash against the one published in latest-mac.yml on the same release — the same applies to latest.yml (Windows) and latest-linux.yml.