Do not file public issues for suspected vulnerabilities. Email the repository maintainers through the security contact configured on GitHub with a minimal reproduction and impact summary.
This project performs local static heuristics. It must not be treated as a complete security boundary.