Report suspected vulnerabilities through GitHub Security Advisories for this
repository or by contacting security@sylphx.ai.
Do not open public issues for vulnerabilities, supply-chain weaknesses, maintainer tokens, publish credentials, or private consumer entity models. If a secret or package-publish credential is exposed, rotate it first, then document the recovery evidence in the owning runbook or incident record.