Please report suspected vulnerabilities privately through GitHub's private vulnerability reporting form. Do not include credentials, tokens, private site profiles, or exploitable details in a public issue.
Include the affected version, the smallest safe reproduction, expected impact, and any suggested mitigation. You should receive an acknowledgement after the report is reviewed.
Security fixes target the latest tagged release. Older releases may be asked to upgrade before a fix is evaluated.
Agent instructions and installer procedures are executable operational input. Review repository changes before allowing an agent to copy skills, run setup tools, or use credentials.