Please open a private GitHub security advisory (or email the maintainer) if you find a security issue. Do not open a public issue for sensitive reports.
Inline Vocab stores API keys only on the user's machine. Do not commit keys, screenshots of Settings that show secrets, or settings.json dumps.