Report suspected vulnerabilities privately to the repository owner rather than opening a public issue with exploit details.
The tools intentionally avoid executing arbitrary repository commands. Users and agents remain responsible for reviewing commands before execution, protecting credentials, isolating test data, and obtaining approval before destructive or privileged actions.
Never place secrets, tokens, production data, or private raw payloads in .project-bootstrap/, .bootstrap/, .loop/, generated audit reports, or loop logs.