Security reports are welcome for path-containment bypasses, archive traversal, secret-detection bypasses with a concrete credential format, dependency compromise, or any behavior that executes or connects to plugin-supplied code.
The project intentionally performs static analysis only. A generated or validated plugin may still contain unsafe executable content; users must review plugins before installing them into a runtime client.
After the public repository exists, use GitHub private vulnerability reporting if it is enabled. Do not place credentials, private keys, customer data, or a working exploit against third-party infrastructure in a public issue.
Until a private reporting channel is published, retain sensitive details and open a minimal public issue requesting maintainer contact without including the vulnerability payload.
Before the first public release, only the local development version exists. The support table will be established during the release gate.