Report security issues privately through the repository owner's GitHub security advisory channel. Do not open a public issue containing exploit details or sensitive repository data.
Version 0.0.1 is the supported development line. Host artifacts and repository evidence are untrusted inputs and must remain behind Runtime/RCCL validation boundaries.