Security reports should target the canonical monorepo:
Archived mirrors are read-only and should not be used for new security reporting.
Use GitHub private vulnerability reporting:
Do not open public issues for exploitable vulnerabilities before maintainers triage and patch.
- Affected module(s):
loom/,kernel/,intelligence/ - Reproducible steps and minimal payload
- Impact assessment (confidentiality/integrity/availability)
- Suggested mitigation or hardening idea (if available)
- Initial acknowledgment target: 72 hours
- Triage status update target: 7 days
- Public disclosure only after patch or explicit maintainer approval