Use GitHub's private vulnerability reporting feature for this repository. Do not open a public issue containing credentials, personal data, private repository names, or exploit details.
Include the affected plugin and skill, reproduction conditions, expected safety boundary, and observed behavior. Remove or replace all sensitive values before submitting.
Security fixes target the latest release on the default branch. Users should update installed plugins before reporting a resolved issue.