Please do not report security issues publicly. Email the project maintainer privately with a description, reproduction steps, and the affected version.
Never include API keys, credentials, personal training data, conversation exports, or generated databases in a report. Redact logs before sharing them.