If you believe you have found a vulnerability in gc-validator, use GitHub private vulnerability reporting on this repository (Security tab). Do not open a public issue for unfixed vulnerabilities.
This project evaluates documentary and runtime predicates against a system description. It does not execute target systems, does not include exploit payloads, and is not a red-team toolkit.
Do not attach employer systems, confidential architecture, or excluded
jurisdiction content (see SCOPE.md) to a report.