Do not open public issues for suspected vulnerabilities. Report them privately
through GitHub's security-advisory interface for colinagent/opagent and
include affected versions, reproduction steps, impact, and any proposed fix.
Only the latest tagged release receives security fixes. The Runtime treats permissions and sandbox setup as fail-closed boundaries; reports showing a bypass of those boundaries are especially valuable.