Security fixes target the latest version on the default branch while the project is experimental.
Use the repository's GitHub Security tab and private vulnerability reporting flow. If private reporting is unavailable, contact the maintainers through a minimal public issue asking for a private channel; do not disclose exploit details, secrets, personal data, or affected targets publicly.
Include impact, reproduction steps, affected files, and a proposed mitigation when possible. Maintainers will acknowledge reports as capacity permits; no response-time guarantee is made.
Relevant reports include prompt injection risks, unintended secret disclosure, unsafe URL handling, and documentation that could lead users to expose sensitive data. Do not test against systems you do not own or have permission to assess.