Please report vulnerabilities privately through the GitHub Security Advisory page of the published repository. Do not open a public issue containing an exploit or credential.
Supported releases follow the latest tagged version. Because DeepSeek Harness is in developer preview, compatibility fixes may require upgrading to a newer DSH release candidate.
The plugin deliberately does not expose arbitrary Git/gh argument execution, credential storage, force push, forced branch deletion, or untracked-file cleanup. Changes that weaken these boundaries require an explicit security review.