A soundness bug in a proof checker is a security bug: it lets a false statement pass as proven. If you find one, please report it privately through GitHub's security advisory feature on this repository rather than as a public issue, and include the smallest export that demonstrates it. You will get a response within a week.