Security reports are accepted for the current default branch. Relevant reports include exposed credentials, unsafe data-loading or deserialization behavior, dependency vulnerabilities, malicious files, privacy risks, and instructions that could cause unintended system changes.
Do not open a public issue for an undisclosed vulnerability. Use GitHub's private vulnerability-reporting feature when available. If it is unavailable, contact the maintainer through the University of Cincinnati research profile.
Include the affected file or dependency, potential impact, safe reproduction steps, and a suggested mitigation if known. Do not include real patient information, live credentials, or harmful payloads. Please coordinate public disclosure until the issue has been assessed and a mitigation or disclosure date is available.
This repository is a research artifact, not a medical device or clinical diagnostic system. Its outputs require independent validation, domain-expert review, and compliance assessment before any real-world use.