Attack on Code logo
ATTACK ON CODE

Security

The CLI never stores GitHub, Google, or provider passwords. Tokens are stored using the operating system credential store when available, with an encrypted local fallback.

Git commands are executed with argument arrays and shell: false.

Repository configuration must not contain access tokens.