Do not open a public issue for a vulnerability that could expose credentials or document data. Report it privately through the repository's GitHub security advisory flow.
Never include a BRAINIALL API key, PDF contents, response contents, or private receipt identifiers in a report. Include the affected version, operating system, Python version, and a minimal synthetic reproduction.