Please do not report security issues with exploit details in public issues.
Use GitHub private vulnerability reporting or a private security advisory for this repository when available. If that is not available, open a minimal public issue asking for a private contact path and leave out sensitive details until a maintainer replies.
Do not attach real .capsule.zip files, Codex history, API keys, tokens, URL
fragments, or other secrets unless a maintainer explicitly asks for sanitized
reproduction material.
For link-sharing issues, include the affected service type, CLI command shape, and expected impact. Do not include the decryption key fragment from a real share link.