DevClean moves developer caches and build artifacts to Trash. It is fail-closed: if a check is unknown, it keeps the file.
Do not run it as root. Auto Clean never prompts for sudo and skips privileged work.
Report vulnerabilities privately. Do not open a public issue with a working exploit against path validation, symlink races, or trash handling.
Expected reports:
- A path that Auto Clean or One-Click would move despite being source, credentials, or a Git worktree
- A symlink or inode swap that bypasses revalidation
- Trash placement outside
~/.Trash
Include OS version, DevClean version, and the candidate path. Do not include secrets.