Do not disclose security issues in public issues. Report a suspected vulnerability privately to the repository maintainers through the security contact configured on GitHub.
Include the affected version, reproduction steps, impact, and any proposed mitigation. Do not include secrets or personal data.
The harness executes commands declared by a repository contract. Treat verification contracts as trusted code, review them before execution, and never run an untrusted contract in a sensitive environment.