This repo carries no application code, no credentials, and no PHI — it's markdown reasoning
content, validated structurally by scripts/validate-vault.sh. There is no code-level
vulnerability surface here in the usual sense.
If a node's reasoning could mislead someone into a harmful decision, or you'd rather not describe the concern in a public issue (for example, because it names a specific harm scenario in detail), use GitHub's private vulnerability reporting rather than SECURITY.md's content-concern issue template. Most content concerns are fine as a public issue — reserve private reporting for the sensitive cases.
We aim to acknowledge reports within 5 business days.