Last updated October 9, 2026
Security
Hybrid can edit files and run commands, so we take security reports seriously. Thank you for helping keep people safe.
Reporting a vulnerability
Please open an issue on GitHub titled “Security”, and keep the details out of it: just say you’ve found something and we’ll reply with a private way to send them. Once we’re talking, include what you found, how to reproduce it, and the Hybrid version (shown in Settings).
We’ll reply as soon as we can, keep you posted while we work on a fix, and credit you in the release notes if you’d like.
What Hybrid asks before doing
Reading code, editing files in your project and running tests happen without interrupting you. These always come to you first, with Approve, Deny or Always allow:
- pushing code to a remote
- deleting files or data
- reading or changing secrets, such as
.envfiles and keys
Every change has a card that opens the developer’s raw transcript, so you can always see exactly what ran.
Your credentials
Hybrid signs in to Claude or Codex through their own tools on your machine. Your provider credentials stay there; we never receive them.
Supported versions
Security fixes go into the latest release. Please keep Hybrid up to date.