Please do not disclose security vulnerabilities in a public issue. Send a private report to itsmebk2007@gmail.com with the affected file or feature, reproduction steps, impact, and any relevant screenshots or logs. Remove secrets from all attachments.
If GitHub private vulnerability reporting is enabled for this repository, you may use the repository’s Security tab instead. The project does not promise a response time or a supported-version service level; reports are reviewed as the maintainer is able.
CraftUI’s optional Cloudflare Workers AI integration runs in the browser. The AI panel sends the supplied bearer token directly to the Cloudflare API and stores the entered token in browser localStorage under the craftui-cf-key key. The account identifier is stored under craftui-cf-id.
Use a narrowly scoped Cloudflare token, never commit .env files or real credentials, and clear the site’s local storage after testing on a shared device. Treat any token used in a public client-side deployment as exposed to that browser’s user.
This policy covers the code and configuration in the CraftUI repository. Third-party services, including Cloudflare Workers AI, are governed by their own security and acceptable-use policies.