Do not report vulnerabilities through a public issue. Follow the Tutti security policy at https://github.com/tutti-os/tutti/security/policy.
Never attach signing keys, access tokens, credentials, complete environment maps, or private Agent prompts to a report.