Do not open public issues for vulnerabilities. Use GitHub's private vulnerability reporting for this repository.
The tool is local-first but its inputs are untrusted. Keep Python current, review paths and generated reports, and use synthetic fixtures in reports. Outputs refuse replacement by default. No security claim makes a parser or native file format a sandbox.