Do not open a public issue for a suspected vulnerability.
Use GitHub's private vulnerability reporting from this repository's Security tab. Include the affected version, impact, minimal reproduction, and any known mitigations. Do not include live credentials or private source code.
Useful reports include secret exposure, command injection, path traversal, unsafe provider execution, sandbox escape, review-bundle boundary failures, and malformed provider output being accepted as a clean review.
Security fixes are applied on a best-effort basis to the latest release and
the latest code on main.