Do not publish exploitable security details before a maintainer has had an opportunity to assess them.
Open a private GitHub security advisory when available, or contact the repository maintainer through the contact method listed in the repository.
Include:
- Affected repository and revision
- Reproduction steps
- Impact assessment
- Suggested mitigation if known
Local-first tools may intentionally operate on local files, SQLite databases, and local model endpoints. Credentials, tokens, private paths, local logs, generated runtime artifacts, and personal data must not be included in public reports or commits.