# Use GitHub for product questions and private security reports.

Wrench is maintained in public by the [Hraness GitHub organization](https://github.com/hraness). The published contact surfaces are the repository issue tracker and GitHub private vulnerability reporting. This project does not publish a telephone number, postal address, or support inbox.

These contact paths match the public v0.16.1 repository metadata and security policy.

## Public product questions

Open a public issue on [github.com/hraness/wrench/issues](https://github.com/hraness/wrench/issues) for defects, documentation gaps, or questions that do not include secrets. Do not paste credentials, authenticated traffic, private content, browser profiles, state directories, or provider account identifiers into a public issue.

## No other published contact channels

Wrench does not publish a telephone number, postal address, or support inbox. Do not treat unofficial mirrors, social replies, or guessed email addresses as maintainer contact. If a report includes secrets, use private vulnerability reporting rather than inventing another channel.

## Security reports

Report suspected vulnerabilities through [GitHub private vulnerability reporting](https://github.com/hraness/wrench/security/advisories/new) for the Wrench repository. That is the path named by the public security policy. Do not open a public issue containing credentials, cookies, tokens, private content, or local paths.

The [security guide](https://wrench.rip/security/) summarizes the local-custody and fail-closed contract that agents should read before binding an account. Source-side policy lives in the repository `SECURITY.md` for v0.16.1.

## Read before you file

Confirm current behavior in the [getting started guide](https://wrench.rip/getting-started/) and [llms.txt](https://wrench.rip/llms.txt) before opening an issue.
