Please report security issues privately through GitHub security advisories if available, or by opening a minimal issue that does not include secrets or exploit details.
Do not attach real diagnostic captures, generated reports, or local inventory unless you have reviewed and sanitized them first.
Before sharing artifacts, remove hostnames, usernames, domains, command-line arguments, environment paths, service or task arguments, secrets, tokens, and local network identifiers.
Collectors should default to least-sensitive output and document any switches that include more detail in the owning skill's safety reference.