Report security issues privately through GitHub Security Advisories when available, or through the Community Access support repository.
Do not publish secrets, tokens, private customer data, or exploit details in public issues or pull requests.
Extension reviewers may reject extensions that collect secrets, exfiltrate data, weaken platform instructions, or encourage unsafe automation.