Personal downstream fork of MoonshotAI/kimi-code with local tweaks. Not intended for upstream merge.
Security reports for the upstream project should go to MoonshotAI/kimi-code. Issues specific to this fork's release artifacts (tag prefix
kimi-code-sanyalnet-cli-) can be reported via tuklusan/kimi-code issues.
Currently, Kimi Code only provides security support for the latest released version.
We take security seriously. Please do not open a public issue for security vulnerabilities.
Preferred channel:
- GitHub Security Advisories — https://github.com/MoonshotAI/kimi-code/security/advisories/new (private disclosure, tracked with the codebase)
Alternative channel:
- Email: code@moonshot.ai (please include "[security]" in the subject)
- Affected version (output of
kimi --version) - Reproduction steps
- Impact assessment
- Any suggested mitigation
We will acknowledge your report and provide an initial assessment as soon as we can.
We will coordinate with you on disclosure timing once a fix is ready.