If a script or document can expose private data, encourage a dangerous command, or mislead someone into damaging the device, report it privately to the maintainer. Do not prove the issue by posting the sensitive material publicly. That would sort of defeat the entire point.
Never publish:
- IMEI, MEID, serial numbers, Android IDs, phone numbers, SIM ICCIDs, IMSIs, or subscriber IDs
- MAC addresses or unique radio calibration data
- Google account data, app data, full unredacted bugreports, or raw userdata
- Attestation keys, Widevine keys, private signing keys, or device-unique encryption material
- Raw protected partition dumps
Run scripts/sanitize-output.py before sharing logs, then review the result yourself. The sanitizer is a backstop, not a magic privacy button.