memblame executes your project's code (pytest tests, scripts or functions) at each commit it measures, in the interpreter you select. Only run it on repositories you trust, and note that the VS Code extension declares itself unsupported in untrusted workspaces for this reason.
Please report security issues privately through GitHub's private vulnerability reporting rather than a public issue. Expect an initial reply within a week.