Do not report credentials, private repository paths, source code, task messages, controller manifests, receipts, or raw tool output in a public issue.
If GitHub shows Report a vulnerability for this repository, use that private channel. If it is unavailable, open a minimal sanitized issue asking the maintainer for a private reporting channel; include no vulnerability details until a private channel is established.
Security fixes must preserve the closed input schemas, exact project/task identity checks, fail-closed filesystem behavior, and least-privilege runtime rules. Use fictional paths and identifiers in every regression test and retained artifact.