Report suspected vulnerabilities through this repository's private GitHub Security Advisory flow. Do not attach real tool catalogs, credentials, or private paths. Include the affected version and a minimized synthetic snapshot.
Only the latest release is supported before 1.0. Unexpected host discovery, network use, arbitrary process launch, unbounded parsing, or retention of raw catalog input outside the explicit caller-controlled flow violates the product security boundary.