Do not open a public issue for a suspected security vulnerability. Email the maintainers through the address listed in the repository owner profile with a description, reproduction steps, and impact.
Contractbot treats contract sources, baseline acceptance, generated patches, and provider credentials as security-sensitive boundaries. Reports involving unexpected source access, baseline changes, credential exposure, or unapproved code changes are especially welcome.