Do not report vulnerabilities through a public issue.
Use this repository's private GitHub security reporting flow.
Include the affected release version, operating system, and a minimal reproduction. Do not include credentials, customer data, prompts, completions, or private traces.