Security fixes are applied to the latest tagged release.
Please report vulnerabilities privately through GitHub Security Advisories once the repository is published. Until then, contact the maintainer privately rather than opening a public issue. Include reproduction steps but never include a real signing token or signed URL.
Links are authenticated local requests, not a remote-access protocol. The handler
requires an HMAC-SHA256 signature from a token containing at least 32 random bytes,
then validates the existing file, cwd, multiplexer, pane, and socket. Normal click
accepts only signed custom schemes; Option-click is an explicit trust action for an
unsigned file:// URL or plain path. Anyone who can read the token can create valid
links with the user's authority. Tokens must be canonical Base64 for at least 32 bytes.
Keep the token mode 0600, do not sync it, and rotate it by uninstalling with --purge
then reinstalling. The scheme does not sandbox Neovim or multiplexer processes.