Please do not open public issues for sensitive security reports.
fm-bench shells out to Apple's local fm command and can optionally store prompts and model outputs in reports. Treat prompt files and JSON reports as potentially sensitive.
If you find a security issue, contact the repository owner privately through GitHub.