Please report security-sensitive issues privately to the maintainer rather than opening a public issue.
Security reports should concern repository-owned code, automation, validation logic, workflows, or documentation that could materially mislead users about a security boundary. Research claims, external systems, and third-party services remain governed by their own evidence and security boundaries.
Do not include credentials, private data, or exploit details in public issues or pull requests.
The repository does not claim to provide a deployed security, authorization, sandboxing, or autonomous-agent control system unless a current executable artifact and repository evidence explicitly establish that capability.