boulder is a maintainer workflow toolkit. It must not be used to scan, probe, or review repositories, systems, or codebases without authorization.
- Do not send secrets, private user data, or protected files to external providers.
- Treat external provider output as advisory until verified locally.
- Record provider usage when it affects a maintainer decision.
Open a GitHub issue with a minimal reproduction and avoid including secrets or private repository data.
Start with a non-sensitive GitHub issue that summarizes the affected command, expected boundary, actual behavior, and reproduction steps. Do not include secrets, credentials, private repository content, or proprietary logs in public reports.