Report malicious or compromised source links, unsafe script behavior, or supply-chain concerns through a private GitHub security advisory when available. Do not disclose active credential or data exposure in a public issue.
Cloud Decision Kit requires no cloud credentials. A change that introduces credential collection, remote execution, a required network service, or a third-party runtime dependency must be treated as security-sensitive and explicitly documented.