Report privately
Use a private GitHub security advisory. Do not publish exploit details, tokens, message content, or personal information in a public issue.
Security model
- Explicit local preview and confirmation before Gmail send.
- Exact
gmail.sendOAuth scope; no inbox-read scope. - Tokens in Windows Credential Manager.
- Queue attachment validation prevents path traversal and symbolic-link substitution.
- No SendArc-operated email relay.
Unsigned beta
Until sustainable code signing is available without a paid commitment, releases may be unsigned. Download only from the official repository and verify SHA256SUMS.txt.