Please report suspected vulnerabilities privately through the repository's security advisories. Do not include credentials, private keys, pairing tokens, sign-in URLs, or QR contents in a public issue.
Include a concise impact description, affected revision, reproduction steps, and any safe mitigation you identified. Maintainers will acknowledge the report and coordinate a private resolution when needed.
This prerelease skill can guide system, network, and authentication changes. Security reports covering unsafe guidance, secret handling, network exposure, or release-distribution integrity are in scope.