Do not disclose suspected vulnerabilities, credentials, or private data in a public issue. Contact the repository maintainers privately through the security reporting channel configured for the public repository.
Include the affected component, reproduction conditions, potential impact, and a minimal proof of concept that contains no private data.
The project must not contain:
- API keys, tokens, passwords, or database credentials;
- identifiable student or staff records;
- private datasets or database dumps;
- raw prompts or model outputs containing private context; or
- internal infrastructure details that are unnecessary for reproduction.