Please do not report vulnerabilities through public issues when the report contains exploitable detail, credentials, private data, or sensitive workflow information.
Use GitHub private vulnerability reporting when it is enabled for the repository. If a repository has its own SECURITY.md, follow that file instead.
Include:
- A concise description of the issue.
- Affected repository, version, commit, or configuration.
- Reproduction steps that do not expose real secrets or private data.
- Expected impact.
- Any safe mitigation you have already identified.
Security relevant reports include credential leakage, unsafe automation, prompt injection routes, privacy leaks, unsafe default configuration, package integrity issues, and bypasses of human approval or audit controls.