Please report vulnerabilities privately through GitHub's security advisory form for this repository. Do not open a public issue with exploit details or sensitive repository information.
Include the affected package and version, impact, reproduction steps, and any suggested mitigation. The maintainers will acknowledge the report and coordinate a fix and disclosure timeline.
Pi packages execute with the permissions granted to Pi. Review package source before use and grant full system or repository permissions only to packages you trust.