Do not report security issues in public issues or pull requests.
Prepare a private report and ask the repository owner or a Humanifest organization owner for the preferred disclosure channel before sending details. Do not include credentials, private research data, or human-subject material in the initial contact.
This project is a local research engine. A vulnerability report should describe the affected command or contract, the version or commit, and the impact on workspace integrity, data exposure, or evidence eligibility. A report is not scientific evidence and does not authorize a public write.