Use GitHub's private vulnerability reporting feature rather than opening a public issue. Reports should contain a minimal synthetic reproducer, never private datasets or prediction artifacts.
CohortShift is not a security boundary or a system for clinical, regulated, or automated deployment decisions. Generated reports and predictions may reflect sensitive source data; keep them access-controlled and review them before sharing.