Report vulnerabilities privately; please do not open a public issue.
Email Timothy.Gregg@complete.tech with the repository, the affected version or commit, and steps to reproduce.
These are volunteer-maintained projects. We aim to acknowledge reports promptly but give no fixed response time.
If you find a leaked key or secret in any repository, report it the same way and rotate it on your side.
Candidate code runs locally with host access and is not a security sandbox; see the safety notes. Never post OAuth files, credentials or raw prompts in an issue.