This project is a static, offline-first browser tool.
- The tool runs locally in the user’s browser.
- Proposal text is not sent to any server by this project.
- If the user enables “Remember pasted text (local)”, the text is stored in browser localStorage on that device.
- A catalog explicitly selected with Upload JSON is also stored in localStorage as a persistent custom override. Reset removes that catalog override and restores the maintained bundled default.
- Citation targets are external sites. The tool does not visit them unless the user follows a link.
Do not paste sensitive proposal text on a shared or untrusted device. Disable “Remember pasted text (local)” when persistence is not appropriate, and clear site data in the browser when device-level removal is required.
Treat every uploaded catalog as untrusted input. The importer validates the current format-v3 structure, upgrades recognized historical format-v2 exports, requires tier values to be the strings "1" or "2", and permits only http: or https: for row citation URLs that the UI can render as links. Catalog strings are displayed as text or escaped before inclusion in generated HTML; catalog JSON is never evaluated as code.
Report and Suggestions CSV exports also neutralize catalog-provided cells that begin with spreadsheet formula markers (=, +, -, @, tab, carriage return, or line feed) by prefixing them with an apostrophe. This keeps uploaded values as text when the CSV is opened in common spreadsheet applications.
Please report any path that bypasses validation, executes catalog-provided markup or script, opens a non-HTTP(S) citation scheme, or causes one user’s locally stored proposal text/catalog to become visible to another origin.
If you discover a security issue (e.g., XSS vectors through catalog rendering), please open a GitHub issue with:
- steps to reproduce
- browser/version
- a minimal example catalog/text
Do not include sensitive proposal content in issues.