Please use GitHub's private vulnerability-reporting flow from the repository's Security tab. Do not open a public issue for credentials, repository-data exposure, sandbox escape, signature or approval bypass, arbitrary publication, or another exploitable vulnerability.
Include the affected commit, reproduction steps, expected impact, and any suggested mitigation. Please avoid accessing data you do not own or testing against third-party repositories without permission.
The most security-sensitive boundaries are repository intake, minimized context, candidate patch policy, offline verification, approval signatures, and GitHub publication. The limitations documented in the README are part of the current security model, not promises of future protection.