Please report security problems privately, not in a public issue or pull request.
Use GitHub's private vulnerability reporting for this repository (you need to be signed in to GitHub): https://github.com/tomevault-io/security-rules/security/advisories/new
Include what you found, how to reproduce it, and what you think the impact is. We will acknowledge the report, keep you updated while we investigate, and credit you in the fix unless you ask us not to.
Report privately: a way to write an instruction file that carries a credential leak, prompt injection, exfiltration or destructive command past these rules, when publishing it would help someone use the gap before it is closed.
Open a normal issue or RFC: false positives, missing coverage that is already publicly known, and proposals for new rules. Rule changes follow the process in RFC.md.
If the problem is in the TomeVault service at tomevault.io rather than in these rules, report it the same way here and say so.
Only the latest rule set version is supported.