Do not commit credentials, cookies, browser profiles, manuscripts, private dashboard exports, personal email addresses, or access tokens.
The public API connector defaults to the documented/observed guest access path. For any authenticated connector, read credentials from environment variables and keep them outside the repository.
Report vulnerabilities through a private GitHub security advisory. Do not open a public issue containing sensitive data.