If you discover a security vulnerability, please report it responsibly:
- Do not open a public issue
- Email the maintainer directly or use GitHub's private vulnerability reporting
claude-profiles manages Claude Code configuration files. Security-relevant areas include:
- Profile name validation (path traversal prevention)
- Shell hook injection (sentinel-bounded, no user input in shell commands)
- File operations (copying config directories)
| Version | Supported |
|---|---|
| 0.2.x | Yes |
| 0.1.x | No |