Tidy changes files on people's computers, so safety bugs matter most. Examples: anything that lets an action escape the folders a user enabled, overwrite a file, touch .git internals, bypass approval, or delete permanently.
Report privately using GitHub's “Report a vulnerability” (Security tab). Please include steps to reproduce on a throwaway folder. We aim to acknowledge within a few days and credit reporters who want it.
Design and threat model: docs/ARCHITECTURE.md. Supported: the latest release.