Security fixes are applied to the latest released version.
Please use GitHub's private security-advisory flow for this repository. Do not open a public issue containing credentials, private interface content, or a working exploit. Include the affected version, reproduction steps, expected impact, and any suggested mitigation.
Design Harness never needs credentials in its Markdown intent files. Optional Agentation storage or MCP use is a separate, explicit opt-in and must remain in development environments.