Please report security issues privately through GitHub Security Advisories rather than opening a public issue.
GeneralAgentHarnessLab redacts common credential shapes before writing traces, but redaction is a safety net, not a guarantee. Review traces before sharing them and never place credentials directly in prompts, tool arguments, source files, or committed configuration.