Please report vulnerabilities privately through GitHub's security advisory interface. Do not place
API secrets, private papers, copyrighted cached PDFs, or local .ragdoll/ databases in reports.
Version 2.x receives security fixes on a best-effort basis. Evidence acquisition, PDF parsing, local
workspace deletion, and external-editor invocation are security-sensitive surfaces; reports should
include the observed behavior and relevant source URL without attaching documents, databases, or
prompt drafts.