Do not open public issues for:
- exposed secrets
- personal data leaks
- approval or safe-mode bypasses
- vulnerabilities that allow unintended access to local files
Instead, send a private report to the maintainer including:
- problem description
- impact
- steps to reproduce
- suggested fix, if available
- the public repository must not contain real personal data
- the local runtime must remain outside version control
- external integrations must be opt-in and approval-gated
- safe mode must remain the default
Valid reports are acknowledged quickly, fixed in a private branch when needed, and disclosed only after a patch is available.